CVE-2026-27119: Svelte
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.
Affected products
- Svelte Svelte: from 5.39.3, before 5.51.5 (fixed in 5.51.5)
Published 2026-02-20. Last modified 2026-06-17.