@angular/compiler is vulnerable to Cross-site Scripting (XSS)
65
Medium Risk
Host bindings could still declare dangerous event-attribute shapes such as names beginning with on or attr.on when the compiler only relied on older checks. The compiler now walks parsed host properties and records parse errors for those patterns, steering authors toward real event bindings instead of DOM event-handler attributes. That closes a class of injection where hostile host metadata could reach the DOM as executable handler attributes in production builds.
You are affected if you are using a version that falls within the vulnerable range.
@angular/compiler is vulnerable to Cross-site Scripting (XSS) in versions 21.0.0 - 21.2.12.
Upgrade the @angular/compiler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant