Junglewise Threat Intelligence

CVE-2026-27902: Svelte XSS via HTML comment injection in SSR error boundary

CVE-2026-27902 · Severity: medium · CVSS 4 · Published 2026-02-26

Technologies: svelte (npm). Vendors: Svelte, npm.

Executive brief

Svelte is a popular JavaScript framework for building web applications. A vulnerability in server-side rendering (SSR) error handling allows attackers to inject malicious HTML and JavaScript code through error messages that are not properly escaped before being embedded in web pages. This could enable attackers to steal user credentials, session tokens, or sensitive data from visitors to affected applications.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in Svelte's error boundary hydration markers used during server-side rendering. The root cause is improper escaping of error messages from the transformError function before they are embedded into HTML output. An attacker who can control the content returned by transformError can inject arbitrary HTML and JavaScript that will execute in users' browsers. The attack requires network access and specific conditions to exploit (high attack complexity and attack requirements present), but does not require authentication or elevated privileges. Affected versions range from 5.53.0 to 5.53.4; the fix is available in version 5.53.5.

Affected products

  • Svelte Svelte 5.53.0 to 5.53.4

Timeline

  • 2026-02-26: disclosed
  • 2026-02-26: patched: Fixed in version 5.53.5

References

Related threats