Intel

AIKIDO-2025-10885

compiler is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2025-66412

85

High Risk

This Affects:

JAVAcompiler
19.0.0 - 21.0.1
Fixed in 21.0.2

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via SVG animation attributeName and MathML/SVG URLs, where SVG animation elements could be exploited to modify the href or xlink:href attributes of other elements to malicious javascript: URLs, allowing an attacker to execute arbitrary JavaScript code by tricking a user into viewing a crafted SVG document.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

compiler is vulnerable to Cross-Site Scripting (XSS) in versions 19.0.0 - 21.0.1.

How to fix this

Upgrade the org.mvnpm.at.angular:compiler library to the patch version.