PT-2026-21306 · Svelte · Svelte

Elliott-With-The-Longest-Name-On-Github

·

Published

2026-02-19

·

Updated

2026-05-14

·

CVE-2026-27121

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Svelte versions prior to 5.51.5
Description Svelte is susceptible to cross-site scripting (XSS) during server-side rendering. Utilizing spread syntax with untrusted data can lead to the inclusion of event handler properties in the generated HTML. An attacker can inject malicious event handlers into the rendered HTML if an application spreads user-controlled or external data as element attributes, resulting in code execution within a victim’s browser. The vulnerability occurs when spreading data as element attributes during server-side rendering.
Recommendations Update to version 5.51.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27121
GHSA-F7GR-6P89-R883
GHSA-PR6F-5X2Q-RWFP

Affected Products

Svelte