CVE-2025-32388

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 79

Summary

CVE-2025-32388 is a vulnerability affecting SvelteKit, a popular framework for building web applications using Svelte. Prior to version 2.20.6, the framework failed to sanitize search parameter names in server load functions, leading to Cross-Site Scripting (XSS) attacks. By crafting a malicious URL, attackers could inject malicious scripts into a user's browser and gain unauthorized access to sensitive information, or perform actions on their behalf. Developers using SvelteKit versions below 2.20.6 are advised to update their framework to address this issue and prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share