{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T04:26:58.011","vulnerabilities":[{"cve":{"id":"CVE-2025-32388","sourceIdentifier":"security-advisories@github.com","published":"2025-04-15T23:15:42.843","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.20.6 , unsanitized search param names cause XSS vulnerability. You are affected if you iterate over all entries of event.url.searchParams inside a server load function. Attackers can exploit it by crafting a malicious URL and getting a user to click a link with said URL. This vulnerability is fixed in 2.20.6."},{"lang":"es","value":"SvelteKit es un framework para desarrollar rápidamente aplicaciones web robustas y de alto rendimiento con Svelte. Antes de la versión 2.20.6, los nombres de parámetros de búsqueda sin sanear causaban una vulnerabilidad XSS. Se ve afectado si se itera sobre todas las entradas de event.url.searchParams dentro de una función de carga del servidor. Los atacantes pueden explotar esta vulnerabilidad manipulando una URL maliciosa y haciendo que el usuario haga clic en un enlace con dicha URL. Esta vulnerabilidad se corrigió en la versión 2.20.6."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/sveltejs/kit/commit/d3300c6a67908590266c363dba7b0835d9a194cf","source":"security-advisories@github.com"},{"url":"https://github.com/sveltejs/kit/releases/tag/%40sveltejs%2Fkit%402.20.6","source":"security-advisories@github.com"},{"url":"https://github.com/sveltejs/kit/security/advisories/GHSA-6q87-84jw-cjhp","source":"security-advisories@github.com"}]}}]}