CVE-2026-27902: Svelte
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.
Affected products
- Svelte Svelte: from 5.53.0, before 5.53.5 (fixed in 5.53.5)
Published 2026-02-26. Last modified 2026-06-17.