CVE-2026-27901Disclosure(svelte / svelte)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • svelte

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
svelte

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 102-2602-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-02-271
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27901: Svelte SSR XSS: When innerText Betrays You In the world of web security, `innerText` is supposed to be the good guy—the safe alternative to the chaotic evil of `innerHTML`. Developers are taught that assigning text to `innerText` autom... https://cvereports.com/reports/CVE-2026-27901

    Post summary

    A new Server‑Side Rendering XSS flaw in Svelte involving innerText is disclosed; no PoC, exploit code, or active exploitation evidence is provided.

    0000040
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27901 Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not pro… https://www.cve.org/CVERecord?id=CVE-2026-27901

    Post summary

    The text references CVE-2026-27901, noting that Svelte’s bind:innerText and bind:textContent on contenteditable elements are vulnerable before version 5.53.5, but provides no PoC, exploit, or patch details.

    00000123
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27901 Cross-Site Scripting in Svelte via Unescaped `bind:innerText` on Contenteditable Elements https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27901

    Post summary

    A new XSS vulnerability (CVE‑2026‑27901) in Svelte involving unescaped bind:innerText on contenteditable elements has been disclosed.

    0000031
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsveltesvelte-node.js-
Appsveltesvelte5.53.5node.js-

Explore more