CVE-2026-27125: Svelte SSR attribute spreading includes inherited properties from prototype chain

Published Feb 19, 2026
·
Updated

In server-side rendering, attribute spreading on elements (e.g. <div {...attrs}>) enumerates inherited properties from the object's prototype chain rather than only own properties. In environments where Object.prototype has already been polluted — a precondition outside of Svelte's control — this can cause unexpected attributes to appear in SSR output or cause SSR to throw errors. Client-side rendering is not affected.

Other sources

svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e.g. <div {...attrs}>) enumerates inherited properties from the object's prototype chain rather than only own properties. In environments where Object.prototype has already been polluted — a precondition outside of Svelte's control — this can cause unexpected attributes to appear in SSR output or cause SSR to throw errors. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

NVD

Affected Software

2 affected componentsFixes available
npm/svelte<=5.51.4
5.51.5
svelte Svelte Node.js<5.51.5

Event History

Feb 19, 2026
Advisory Published
via GitHub·08:28 PM
Data Sourced
via GitHub·08:28 PM
DescriptionWeaknessAffected Software
Feb 20, 2026
CVE Published
via MITRE·10:29 PM
Data Sourced
via MITRE·10:29 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 23, 58126
Event
via FIRST·10:55 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-27125?

CVE-2026-27125 is considered a moderate severity vulnerability due to its potential impact on server-side rendering behavior.

2

How do I fix CVE-2026-27125?

To fix CVE-2026-27125, update Svelte to version 5.51.5 or later.

3

What is the affected software for CVE-2026-27125?

CVE-2026-27125 affects Svelte versions up to 5.51.4.

4

What type of vulnerability is CVE-2026-27125?

CVE-2026-27125 is a vulnerability related to attribute spreading in server-side rendering that exposes inherited prototype properties.

5

When was CVE-2026-27125 published?

CVE-2026-27125 was published in 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203