VYPR

npm package

svelecte

pkg:npm/svelecte

Vulnerabilities (1)

  • CVE-2023-38687MedAug 14, 2023
    affected < 3.16.3fixed 3.16.3

    Svelecte is a flexible autocomplete/select component written in Svelte. Svelecte item names are rendered as raw HTML with no escaping. This allows the injection of arbitrary HTML into the Svelecte dropdown. This can be exploited to execute arbitrary JavaScript whenever a Svelecte