Intel

AIKIDO-2025-10885

compiler is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2025-66412 Published Dec 5, 2025

85

High Risk

This Affects:

JAVAcompiler
19.0.0 - 21.0.1
Fixed in 21.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via SVG animation attributeName and MathML/SVG URLs, where SVG animation elements could be exploited to modify the href or xlink:href attributes of other elements to malicious javascript: URLs, allowing an attacker to execute arbitrary JavaScript code by tricking a user into viewing a crafted SVG document.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

compiler is vulnerable to Cross-Site Scripting (XSS) in versions 19.0.0 - 21.0.1.

How to fix this

Upgrade the org.mvnpm.at.angular:compiler library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform