关键漏洞信息 漏洞标题 XSS during SSR with contenteditable and 威胁等级 Moderate 描述 The contents of and on elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial value on the server. 影响版本 <=5.53.4 修复版本 5.53.5 CVSS v4 基本指标 严重性:5.3 / 10 (Moderate) 利用性指标: - Attack Vector: Network - Attack Complexity: High - Attack Requirements: Present - Privileges Required: None - User Interaction: Passive 脆弱系统影响指标: - Confidentiality: Low - Integrity: None - Availability: None 后续系统影响指标: - Confidentiality: High - Integrity: High - Availability: None CVE ID CVE-2026-27901 弱点 No CWEs 贡献者 elliott-with-the-longest-name-on-github (Remediation reviewer) KarimPwnz (Remediation developer)