How to use this reference
Compare all fields crossing rendering contexts, including metadata keys. The researcher describes replacement with an HTML-safe serializer and regression coverage. The maintainer identifies Svelte 5.46.4 as patched. Preserve one encoding contract across keys and values, rather than treating valid JSON as sufficient for every output context.
Before reading
- Server-side rendering and framework integration concepts
- Basic trust-boundary and secure-input review
Context and limits
- Affected behavior requires experimental async rendering and hydration keys influenced by untrusted input; ordinary Svelte use alone does not establish exposure.
- The advisory version table lists 5.46.0 through 5.46.3, while its summary says 5.46.0-2; the researcher and Fluid Attacks advisory support the broader table range.
- March 17 is the article publication; the researcher dates the separate fix and disclosure to January 15, 2026. Learning prerequisites are editorial.
Sources and provenance
- CVE-2025-15265: Svelte Hydratable Key SSR XSS - Lydian Camilo Vera · reviewed 2026-10-03
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in svelte Svelte · reviewed 2026-10-03
- Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR) Fluid Attacks · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.