Логотип exploitDog
bind:CVE-2026-27122
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-27122

Количество 3

Количество 3

redhat логотип

CVE-2026-27122

около 1 месяца назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-27122

около 1 месяца назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-m56q-vw4c-c2cp

около 1 месяца назад

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-27122

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.6
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-27122

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-m56q-vw4c-c2cp

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу