Medium severity5.4NVD Advisory· Published Feb 20, 2026· Updated Jun 17, 2026
CVE-2026-27122
CVE-2026-27122
Description
svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sveltenpm | < 5.51.5 | 5.51.5 |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/wolfi/langfuse-3-workerpkg:npm/svelte
< 3.163.0-r0+ 3 more
- (no CPE)range: < 3.163.0-r0
- (no CPE)range: < 3.163.0-r0
- (no CPE)range: < 3.163.0-r0
- (no CPE)range: < 5.51.5
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-m56q-vw4c-c2cpghsaADVISORY
- github.com/sveltejs/svelte/security/advisories/GHSA-m56q-vw4c-c2cpnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-27122ghsaADVISORY
News mentions
0No linked articles in our index yet.