CVE-2026-27212Disclosure(swiperjs / swiper)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch swiperjs swiper systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vulnerability resides in line 94 of shared/utils.mjs, where the indexOf() function is used to check whether user provided input contain forbidden strings. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. The exploit works across Windows and Linux and on Node and Bun runtimes. Any application that processes attacker-controlled input using this package may be affected by the following: Authentication Bypass, Denial of Service and RCE. This issue is fixed in version 12.1.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • swiper

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-24); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
swiper

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-25: 1Mentions · 2026-08-10: 2PoC Mentioned / Linked · 2026-08-10: 2Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-08-10: 2Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 1Technical Details · 2026-08-10: 202-2402-2508-10
Signal classification4 categories
Disclosure
228.6%
Patch
228.6%
PoC
228.6%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure2General1Patch1
2026-02-251
Patch1
2026-08-102
PoC2
Full discourse7 posts
  • Pentester Academy@SecurityTube
    PoC

    The patch was there. The vulnerability was too. CVE-2026-27212 puts you inside a critical Swiper JS prototype pollution flaw where one small bypass changes everything. Your objective: break the patch. Enter Skill Dive → https://bit.ly/3TMUKEu https://t.co/N1tYET9ZvK

    Post summary

    The tweet highlights a critical prototype pollution vulnerability in Swiper JS (CVE‑2026‑27212), notes that a patch exists, and provides a link that likely shares a proof‑of‑concept or exploit to bypass that patch.

    000723.0K
    199.3K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical prototype pollution flaw (CVE-2026-27212) in the Swiper npm package allows RCE, DoS, and auth bypass. Update to version 12.1.2 immediately. #Swiper #CVE202627212 #PrototypePollution #CyberSecurity #AppSec #npm #JavaScript #InfoSec https://securityonline.info/cve-2026-27212-critical-swiper-prototype-pollution-flaw-cvss-9-4-exposes-global-apps/

    Post summary

    The post announces a critical prototype pollution flaw in Swiper (CVE‑2026‑27212) that enables RCE, DoS, and auth bypass, and urges users to update to version 12.1.2 immediately.

    10040425
    10.4K followersView on X
  • INE Security (FKA eLearnSecurity)@INEsecurity
    PoC

    The patch was there. The vulnerability was too. CVE-2026-27212 puts you inside a critical Swiper JS prototype pollution flaw where one small bypass changes everything. Your objective: break the patch. Enter Skill Dive → https://bit.ly/4hUWSnE https://t.co/4eiHIWx5cS

    Post summary

    The message announces a critical prototype‑pollution flaw in Swiper JS, notes that a patch exists, and provides a link that likely contains a Proof of Concept encouraging readers to bypass the patch.

    000121.6K
    47.3K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    CVE-2026-27212: ثغرة خطيرة في Swiper تم اكتشاف ثغرة Prototype Pollution شديدة الخطورة في مكتبة Swiper، وهي شائعة الاستخدام في تطبيقات الويب والجوال لإنشاء سلايدرات تفاعلية. تحمل الثغرة تصنيف CVSS 9.4، مما يعني تأثيرها واسع النطاق وقدرتها على تعريض تطبيقات عالمية للخطر. يمكن للمهاجمين استغلال هذه الثغرة لتنفيذ تعليمات برمجية عن بعد. 💡 الحماية: - تحديث مكتبة Swiper إلى أحدث إصدار متوفر. - مراجعة الكود والتأكد من عدم وجود استدعاءات غير آمنة لوظائف Swiper. - تطبيق مبدأ أقل الامتيازات على الوصول إلى الموارد. 🔗 https://securityonline.info/cve-2026-27212-critical-swiper-prototype-pollution-flaw-cvss-9-4-exposes-global-apps/ #الأمن_السيبراني #Swiper #CVE

    Post summary

    A critical prototype pollution vulnerability (CVE-2026-27212) in Swiper with CVSS 9.4 is disclosed, and users are advised to update the library and apply mitigation steps.

    0002063
    53 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-27212: 重大なSwiperプロトタイプ汚染脆弱性(CVSS 9.4)により、世界中のアプリが危険にさらされる CVE-2026-27212: Critical Swiper Prototype Pollution Flaw (CVSS 9.4) Exposes Global Apps #DailyCyberSecurity (Feb 24) https://securityonline.info/cve-2026-27212-critical-swiper-prototype-pollution-flaw-cvss-9-4-exposes-global-apps/

    Post summary

    The post announces a new high‑severity prototype‑pollution vulnerability (CVE‑2026‑27212) affecting Swiper, with a CVSS score of 9.4, but provides no details on exploitation or mitigation.

    00020351
    4.7K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    CVE-2026-27212: Critical Swiper Prototype Pollution Flaw (CVSS 9.4) Exposes Global Apps https://securityonline.info/cve-2026-27212-critical-swiper-prototype-pollution-flaw-cvss-9-4-exposes-global-apps/

    Post summary

    A new critical prototype pollution vulnerability (CVE-2026-27212) in Swiper with CVSS 9.4 that can expose global apps has been disclosed.

    0000041
    71 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-27212 from https://vulntracker.io/cves/CVE-2026-27212

    Post summary

    The tweet simply directs readers to a link for full details on CVE-2026-27212, without providing additional information.

    0000064
    336 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appswiperjsswiper-node.js-

Explore more