@angular/core is vulnerable to Cross-Site Scripting (XSS)
76
High Risk
Angular contains a cross-site scripting (XSS) vulnerability in its internationalization (i18n) pipeline. Applications that mark static event handler attributes (such as onerror or onclick) for translation using i18n-on* may allow a malicious translation file to replace benign handlers with arbitrary JavaScript, resulting in code execution in users' browsers. Successful exploitation requires an attacker to control or influence the translation files used during localization.
You are affected if you are using a version that falls within the vulnerable range. And you are using Angular's i18n functionality and mark static event handler attributes (such as onerror or onclick) for translation using i18n-on*.
@angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 20.3.26, 21.0.0 - 21.2.18 and 22.0.0 - 22.0.0.
Upgrade the @angular/core and @angular/compiler library to the patch version. If this is not possible, do not mark event handler attributes for translation using i18n-on*, and only use translation files from trusted sources.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant