CVE-2026-27119: Svelte affected by XSS in SSR `<option>` element
In certain circumstances, the server-side rendering output of an <option> element does not properly escape its content, potentially allowing HTML injection in the SSR output. Client-side rendering is not affected.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27119 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →