CVE-2026-27122
ADVISORY - githubSummary
When using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected.
Common Weakness Enumeration (CWE)
ADVISORY - github
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-m56q-vw4c-c2cp
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)