CVE-2026-27902

Source
https://cve.org/CVERecord?id=CVE-2026-27902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27902
Aliases
Published
2026-02-26T00:58:54.604Z
Modified
2026-03-03T02:56:47.116631Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers
Details

Svelte performance oriented web framework. Prior to version 5.53.5, errors from transformError were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from transformError. Version 5.53.5 fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27902.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/sveltejs/svelte

Affected ranges

Type
GIT
Repo
https://github.com/sveltejs/svelte
Events

Affected versions

svelte@5.*
svelte@5.53.0
svelte@5.53.1
svelte@5.53.2
svelte@5.53.3
svelte@5.53.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27902.json"