LOW🇬🇧 English

CVE-2024-53262

CVSS 2.0v4.0pub. 2024-11-25upd. 2025-08-28

SvelteKit to framework do szybkiego tworzenia solidnych i wydajnych aplikacji webowych z wykorzystaniem Svelte. Statyczny szablon error.html zawiera placeholdery, które są zastępowane bez wcześniejszego escape'owania treści. error.html jest stroną renderowaną, gdy wszystko inne zawiedzie i może zawierać następujące placeholdery: %sveltekit.status% — status HTTP oraz %sveltekit.error.message% — komunikat błędu. Prowadzi to do możliwej injection, jeśli aplikacja jawnie tworzy błąd z wiadomością zawierającą dane kontrolowane przez użytkownika. Podatne są jedynie aplikacje, w których dane wejściowe od użytkownika są użyte w komunikacie `Error`, dlatego zdecydowana większość aplikacji nie będzie podatna. Problem został rozwiązany w wersji 2.8.3 i zaleca się wszystkim użytkownikom aktualizację. Brak znanych obejść dla tej podatności.

Pokaż oryginał (EN)

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping the content first. error.html is the page that is rendered when everything else fails. It can contain the following placeholders: %sveltekit.status% — the HTTP status, and %sveltekit.error.message% — the error message. This leads to possible injection if an app explicitly creates an error with a message that contains user controlled content. Only applications where user provided input is used in the `Error` message will be vulnerable, so the vast majority of applications will not be vulnerable This issue has been addressed in version 2.8.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Svelte Sveltekit

    APP
    Svelte
    < 2.8.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2023-29008HIGH8.8ten sam produkt

The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+s...

CVE-2023-29003HIGH8.8ten sam produkt

SvelteKit is a web development framework. The SvelteKit framework offers developers an option to create simple...

CVE-2024-53261LOW2.0ten sam produkt

SvelteKit to framework do szybkiego tworzenia solidnych i wydajnych aplikacji internetowych przy użyciu Svelte...

CVE-2026-42570HIGH7.5ten sam vendor

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficien...

CVE-2026-40073HIGH8.2ten sam vendor

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.5...