{"id":"CVE-2025-32388","aliases":["GHSA-6q87-84jw-cjhp"],"url":"https://o3.security/vulnerability/CVE-2025-32388","summary":"SvelteKit allows XSS via tracked search_params","details":"SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searchParams inside a server load function. Attackers can exploit it by crafting a malicious URL and getting a user to click a link with said URL. This vulnerability is fixed in 2.20.6.","published":"2025-04-15T22:32:06.059Z","modified":"2026-08-08T03:47:52.956986966Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@sveltejs/kit","fixedVersion":"2.20.6"}],"fix":{"url":"https://github.com/sveltejs/kit/commit/d3300c6a67908590266c363dba7b0835d9a194cf","label":"sveltejs/kit@d3300c6"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.20.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32388.json"},{"type":"ADVISORY","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-6q87-84jw-cjhp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32388"},{"type":"FIX","url":"https://github.com/sveltejs/kit/commit/d3300c6a67908590266c363dba7b0835d9a194cf"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:52.956986966Z"}}