{"id":"CVE-2026-27901","aliases":["GHSA-phwv-c562-gvmh"],"url":"https://o3.security/vulnerability/CVE-2026-27901","summary":"Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`","details":"Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. Version 5.53.5 fixes the issue.","published":"2026-02-26T00:57:40.269Z","modified":"2026-07-15T01:48:54.285727831Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"svelte","fixedVersion":"5.53.5"}],"fix":{"url":"https://github.com/sveltejs/svelte/commit/0df5abcae223058ceb95491470372065fb87951d","label":"sveltejs/svelte@0df5abc"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/svelte/releases/tag/svelte%405.53.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27901.json"},{"type":"ADVISORY","url":"https://github.com/sveltejs/svelte/security/advisories/GHSA-phwv-c562-gvmh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27901"},{"type":"FIX","url":"https://github.com/sveltejs/svelte/commit/0df5abcae223058ceb95491470372065fb87951d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:54.285727831Z"}}