Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rcqx-6q8c-2c42 | Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State |
Tue, 23 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Tue, 09 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Svelte
Svelte svelte |
|
| Vendors & Products |
Svelte
Svelte svelte |
Tue, 09 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7. | |
| Title | Svelte: XSS via DOM Clobbering of Internal Framework State | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-30T02:46:14.901Z
Reserved: 2026-04-28T17:26:12.084Z
Link: CVE-2026-42573
Updated: 2026-06-09T18:25:45.872Z
Status : Analyzed
Published: 2026-06-09T17:17:07.400
Modified: 2026-06-11T18:46:50.667
Link: CVE-2026-42573
OpenCVE Enrichment
Updated: 2026-06-09T20:00:17Z
Github GHSA