CVE-2026-27902: Svelte

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.

Affected products

  • Svelte Svelte: from 5.53.0, before 5.53.5 (fixed in 5.53.5)

Published 2026-02-26. Last modified 2026-06-17.