PT-2026-21305 · Svelte · Svelte

Elliott-With-The-Longest-Name-On-Github

·

Published

2026-02-19

·

Updated

2026-03-06

·

CVE-2026-27119

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Svelte versions 5.39.3 through 5.51.4
Description Svelte is susceptible to a flaw where, under specific conditions, the server-side rendering of an <option> element fails to properly escape its content. This can lead to potential HTML injection within the server-side rendered output. Client-side rendering is not impacted by this issue.
Recommendations Update to version 5.51.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27119
GHSA-H7H7-MM68-GMRC

Affected Products

Svelte