Junglewise Threat Intelligence

CVE-2026-27122: Svelte SSR HTML injection in svelte:element tag validation

CVE-2026-27122 · Severity: medium · CVSS 4 · Published 2026-02-19

Technologies: svelte (npm). Vendors: Svelte, npm.

Executive brief

Svelte is a popular JavaScript framework used to build web applications with server-side rendering (SSR). When using the `<svelte:element>` component with dynamic tag names, Svelte SSR fails to validate or sanitize the tag name before outputting it to HTML, allowing attackers to inject arbitrary HTML and potentially execute malicious scripts in the rendered page.

Technical details

The vulnerability is an HTML injection flaw (CWE-79) in Svelte's server-side rendering engine. When the `<svelte:element this={tag}>` component is used with a user-controlled or attacker-supplied tag name, the tag value is not validated before being emitted into the HTML output, allowing special characters and HTML markup to be injected. Client-side rendering is not affected. The attack requires network access and high privileges (an attacker must be able to provide input that influences the tag parameter). This can lead to HTML injection in SSR output with potential impact on confidentiality and integrity of subsequent systems. The vulnerability affects Svelte versions up to and including 5.51.4, and is patched in version 5.51.5 and later.

Affected products

  • Svelte Svelte <=5.51.4

Timeline

  • 2026-02-19: disclosed: GHSA-m56q-vw4c-c2cp published
  • 2026-02-19: patched: Fixed in version 5.51.5
  • 2026-02-20: other: CVE-2026-27122 published on NVD

References

Related threats