Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7. | |
| Title | Svelte: XSS via DOM Clobbering of Internal Framework State | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T18:25:49.121Z
Reserved: 2026-04-28T17:26:12.084Z
Link: CVE-2026-42573
Updated: 2026-06-09T18:25:45.872Z
Status : Undergoing Analysis
Published: 2026-06-09T17:17:07.400
Modified: 2026-06-09T19:32:29.743
Link: CVE-2026-42573
No data.
OpenCVE Enrichment
Updated: 2026-06-09T18:30:11Z