Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27122

Опубликовано: 20 фев. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:svelte:svelte:*:*:*:*:*:node.js:*:*
Версия до 5.51.5 (исключая)

EPSS

Процентиль: 1%
0.00011
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.6
redhat
около 1 месяца назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

github
около 1 месяца назад

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

EPSS

Процентиль: 1%
0.00011
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79