CVE-2025-15265

medium Red Hat
CVSS v3 Base Score
6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published: January 15, 2026
Last Modified: January 15, 2026
Vendor: Red Hat

Description

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, with potential for session theft and account compromise. This issue affects Svelte: from 5.46.0 before 5.46.3.

CWE

CWE-79

Affected Products

Red Hat Build of Podman Desktop - Tech Preview

References

to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, with potential for session theft and account compromise.\nThis issue affects Svelte: from 5.46.0 before 5.46.3.","publishedDate":"2026-01-15T19:59:41Z","lastModifiedDate":"2026-01-15T19:59:41Z","cweId":"CWE-79","references":["https://bugzilla.redhat.com/show_bug.cgi?id=2430177","https://www.cve.org/CVERecord?id=CVE-2025-15265","https://nvd.nist.gov/vuln/detail/CVE-2025-15265","https://fluidattacks.com/advisories/lydian","https://github.com/sveltejs/svelte/security/advisories/GHSA-6738-r8g5-qwp3"],"affectedProducts":["Red Hat Build of Podman Desktop - Tech Preview"],"fixAvailable":null} to terminate the","datePublished":"2026-01-15T19:59:41Z","author":{"@type":"Organization","name":"Red Hat"},"publisher":{"@type":"Organization","name":"CyberWatcher"}}