Loading
Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the issue.
Cite this page
CVE-2026-27902. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-27902
Use CWE-79, Svelte vendor hub and Svelte product page to widen CVE-2026-27902 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-29261, CVE-2024-45047 and CVE-2022-25875 for nearby disclosures in the same product family.