@angular/core is vulnerable to Cross-Site Scripting (XSS)
53
Medium Risk
Angular's DOM security schema and template compiler fail to sanitize several SVG, namespace, and i18n attribute bindings before the patched releases. Dynamic href and xlink:href values on SVG link elements, namespaced SVG script markup, and custom-namespaced HTML tags can bypass URL sanitization when bound to untrusted input. Prior versions also allow dynamically mounting components onto script hosts. The patch aligns compiler and runtime schemas, strips dangerous SVG script markup at compile time, sanitizes SVG link URLs, normalizes namespace lookups, and rejects script component hosts.
You are affected if you are using a version that falls within the vulnerable range.
@angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 21.0.0 - 21.2.14, 20.0.0 - 20.3.21 and 19.0.0 - 19.2.22.
Upgrade the @angular/core and/or the @angular/compiler library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant