CVE-2025-27109

HIGH

solid-js <1.9.4 - XSS

Title source: llm
STIX 2.1

Description

solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX fragments. This issue has been addressed in version 1.9.4 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 7.3
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-116 CWE-79
Status published
Products (2)
npm/solid-js 0 - 1.9.4npm
solidjs/solid < 1.9.4
Published Feb 21, 2025
Tracked Since Feb 18, 2026