Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27119

Опубликовано: 20 фев. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
Версия от 5.39.3 (включая) до 5.51.5 (исключая)

EPSS

Процентиль: 1%
0.00009
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.6
redhat
около 1 месяца назад

svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

github
около 1 месяца назад

Svelte affected by XSS in SSR `<option>` element

EPSS

Процентиль: 1%
0.00009
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79