CVE-2026-27121 – Svelte affected by cross-site scripting via spread attributes in Svelte SSR
CVE ID : CVE-2026-27121
Published : Feb. 20, 2026, 10:27 p.m. | 35 minutes ago
Description : svelte performance oriented web framework. Versions of svelte prior to 5.51.5 are vulnerable to cross-site scripting (XSS) during server-side rendering. When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims’ browsers. This vulnerability is fixed in 5.51.5.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more…