Svelte: XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Description
Published by the National Vulnerability Database
Feb 26, 2026
Published to the GitHub Advisory Database
Feb 26, 2026
Reviewed
Feb 26, 2026
Last updated
Feb 26, 2026
Errors from
transformErrorwere not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned fromtransformError.References