OSS Support Hub / UI Library

Node.js UI Library MIT Latest: svelte@5.55.7

Svelte

Cybernetically enhanced web apps with a compiler-based approach

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
86.6K+5
GitHub Stars
๐Ÿ“ฆ
svelte@5.55.7
Latest Release ยท Yesterday
๐Ÿ”„
6d
Avg. Release Cadence
๐Ÿ›
1.0K
Open Issues
๐Ÿ“…
Yesterday
Last Commit
โฌ‡๏ธ
4.0M
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

svelte vulnerable to Cross-site Scripting

Published: 2026-01-15 Fixed in: 5.46.4

Svelte has a potential mXSS vulnerability due to improper HTML escaping

Published: 2024-08-30 Fixed in: 4.2.19

Svelte: ReDoS in `<svelte:element>` Tag Validation

Published: 2026-05-14 Fixed in: 5.55.7

Svelte SSR attribute spreading includes inherited properties from prototype chain

Published: 2026-02-19 Fixed in: 5.51.5

Svelte: SSR XSS via Insecure Promise Serialization in hydratable

Published: 2026-05-14 Fixed in: 5.55.7

Svelte affected by cross-site scripting via spread attributes in Svelte SSR

Published: 2026-02-19 Fixed in: 5.51.5

svelte is vulnerable to XSS with textarea bind:value

Published: 2026-01-16 Fixed in: 3.59.2

Svelte affected by XSS in SSR `<option>` element

Published: 2026-02-19 Fixed in: 5.51.5

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

Published: 2026-02-19 Fixed in: 5.51.5

Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Published: 2026-02-26 Fixed in: 5.53.5

Alternatives to Svelte

Other UI Library projects in the Node.js ecosystem worth evaluating.

Support Options for Svelte

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Svelte โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’