Intel

AIKIDO-2025-10979

@kolkov/angular-editor is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 26, 2025

66

Medium Risk

This Affects:

JS@kolkov/angular-editor
2.2.0 - 3.0.3
Fixed in 3.0.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) via Unsafe Preview Rendering due to improper neutralization of user input during web page generation. The vulnerability exists because user-supplied HTML, including attributes like onerror, is rendered without adequate sanitization when switching from code to preview mode. An attacker can exploit this by tricking a user into submitting a malicious payload, which executes arbitrary JavaScript in the victim's browser when the preview is rendered.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@kolkov/angular-editor is vulnerable to Cross-Site Scripting (XSS) in versions 2.2.0 - 3.0.3.

How to fix this

Upgrade the @kolkov/angular-editor library to the patch version.