CVE-2026-27119

MEDIUM

svelte 5.39.3-5.51.4 - Cross-Site Scripting in Server-Side Rendering Option Element

Title source: llm
STIX 2.1

Description

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
npm/svelte 5.39.3 - 5.51.5npm
svelte/svelte 5.39.3 - 5.51.5
Published Feb 20, 2026
Tracked Since Feb 21, 2026