{"id":"GHSA-f3cj-j4f6-wq85","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f3cj-j4f6-wq85","summary":"Svelte: SSR XSS via Insecure Promise Serialization in hydratable","details":"Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true:\n- you are using `hydratable` (an experimental feature at the time of this report)\n- you are passing attacker-controlled input such that a synchronous value is hydrated, then a promise value, e.g. `hydratable('someKey', () => [synchronousValue, promiseValue])`","published":"2026-05-14T20:30:09Z","modified":"2026-05-14T20:49:54.154680Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"svelte","fixedVersion":"5.55.7"}],"fix":{"url":"https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4","label":"sveltejs/svelte@a16ebc6"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/svelte/security/advisories/GHSA-f3cj-j4f6-wq85"},{"type":"WEB","url":"https://github.com/sveltejs/svelte/commit/a16ebc67bbcf8f708360195687e1b2719463e1a4"},{"type":"PACKAGE","url":"https://github.com/sveltejs/svelte"},{"type":"WEB","url":"http://github.com/sveltejs/svelte/releases/tag/svelte%405.55.7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-14T20:49:54.154680Z"}}