@angular/core is vulnerable to Cross-site Scripting (XSS)
59
Medium Risk
The Angular runtime allows template and host bindings to attr.on* event-handler attributes to bypass production-mode validation and write attacker-controlled inline handlers into the DOM. When a victim clicks the affected element, the browser executes the injected JavaScript in the application origin. The fix enforces runtime rejection of on* attribute bindings regardless of build mode.
You are affected if you are using a version that falls within the vulnerable range.
@angular/core is vulnerable to Cross-site Scripting (XSS) in versions 21.0.0 - 21.2.12, 20.0.0 - 20.3.19 and 19.0.0 - 19.2.21.
Upgrade the @angular/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant