Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.
Cite this page
CVE-2026-27901. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-27901
Use CWE-79, Svelte vendor hub and Svelte product page to widen CVE-2026-27901 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-29261, CVE-2024-45047 and CVE-2022-25875 for nearby disclosures in the same product family.