Junglewise Threat Intelligence

CVE-2026-27901: Svelte XSS in SSR with contenteditable bind:innerText and bind:textContent

CVE-2026-27901 · Severity: medium · CVSS 4 · Published 2026-02-26

Technologies: svelte (npm). Vendors: Svelte, npm.

Executive brief

Svelte is a popular JavaScript framework for building interactive web applications. When using server-side rendering (SSR) with contenteditable elements, the framework failed to properly escape the initial values of bind:innerText and bind:textContent bindings, allowing attackers to inject malicious HTML and JavaScript code. An attacker who can control the data rendered as the binding's initial value could execute arbitrary code in users' browsers.

Technical details

This vulnerability is a Cross-Site Scripting (XSS) issue (CWE-79) in Svelte's server-side rendering implementation. The root cause is improper escaping of user-supplied data when rendering contenteditable elements with bind:innerText and bind:textContent bindings. The attack vector is network-based and requires user interaction (passive) and specific attack prerequisites. During SSR, if untrusted data is used as the initial value for these bindings, the unescaped content is injected into the DOM as HTML rather than plain text, enabling HTML injection and XSS attacks. The vulnerability affects Svelte versions up to and including 5.53.4, and has been fixed in version 5.53.5.

Affected products

  • Svelte Svelte up to 5.53.4

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Fixed in version 5.53.5

References

Related threats