CVE-2026-27119

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.
Configurations

Configuration 1 (hide)

cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*

History

23 Feb 2026, 20:54

Type Values Removed Values Added
First Time Svelte svelte
Svelte
References () https://github.com/sveltejs/svelte/security/advisories/GHSA-h7h7-mm68-gmrc - () https://github.com/sveltejs/svelte/security/advisories/GHSA-h7h7-mm68-gmrc - Vendor Advisory
CPE cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-02-23 20:54


NVD link : CVE-2026-27119

Mitre link : CVE-2026-27119

CVE.ORG link : CVE-2026-27119


JSON object : View

Products Affected

svelte

  • svelte
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')