Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7. | |
| Title | Svelte: XSS via DOM Clobbering of Internal Framework State | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T18:25:49.121Z
Reserved: 2026-04-28T17:26:12.084Z
Link: CVE-2026-42573
No data.
Status : Received
Published: 2026-06-09T17:17:07.400
Modified: 2026-06-09T17:17:07.400
Link: CVE-2026-42573
No data.
OpenCVE Enrichment
Updated: 2026-06-09T18:30:11Z