compiler is vulnerable to Cross-Site Scripting (XSS)
85
High Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via SVG animation attributeName and MathML/SVG URLs, where SVG animation elements could be exploited to modify the href or xlink:href attributes of other elements to malicious javascript: URLs, allowing an attacker to execute arbitrary JavaScript code by tricking a user into viewing a crafted SVG document.
You are affected if you are using a version that falls within the vulnerable range.
compiler is vulnerable to Cross-Site Scripting (XSS) in versions 19.0.0 - 21.0.1.
Upgrade the org.mvnpm.at.angular:compiler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant