Package Health

@angular/compiler

Angular - the compiler library

Latest 22.2.2NPMNPM

94%

Total Score

healthy

Active Angular releases and a broad, productive contributor base make this a well-supported package.

Are you affected? Scan for Free

Health Score Breakdown

All health scores are okay.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-69151
@angular/compiler is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 22.0.0-next.0 - 22.0.1, 21.0.0-next.0 - 21.2.19, 20.0.0-next.0 - 20.3.27 and 0.0.0 - 19.2.25.
0.0.0 - 19.2.2520.0.0-next.0 - 20.3.2721.0.0-next.0 - 21.2.19 +1 more
High
CVE-2026-54265
@angular/compiler is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 22.0.0-next.0 - 22.0.1, 21.0.0-next.0 - 21.2.17, 20.0.0-next.0 - 20.3.25 and 0.0.0 - 19.2.25.
0.0.0 - 19.2.2520.0.0-next.0 - 20.3.2521.0.0-next.0 - 21.2.17 +1 more
Medium
AIKIDO-2026-10836 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@angular/compiler is vulnerable to Cross-site Scripting (XSS) in versions 21.0.0 - 21.2.12.
21.0.0 - 21.2.12
Medium
CVE-2026-22610
@angular/compiler is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 21.1.0-next.0 - 21.1.0-rc.0, 21.0.0-next.0 - 21.0.7, 20.0.0-next.0 - 20.3.16, 19.0.0-next.0 - 19.2.18 and 0.0.0 - 18.2.14.
0.0.0 - 18.2.1419.0.0-next.0 - 19.2.1820.0.0-next.0 - 20.3.16 +2 more
High
CVE-2025-66412
@angular/compiler is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 21.0.0-next.0 - 21.0.2, 20.0.0-next.0 - 20.3.15, 19.0.0-next.0 - 19.2.17 and 0.0.0 - 18.2.14.
0.0.0 - 18.2.1419.0.0-next.0 - 19.2.1720.0.0-next.0 - 20.3.15 +1 more
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.3.0
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
10 years ago
Unpacked Size
4.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform