CVE-2026-42573

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This issue has been patched in version 5.55.7.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:* 5.55.7 (excluding)