CVE-2026-27119
ADVISORY - githubSummary
In certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-27119
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.1mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-h7h7-mm68-gmrc
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)