Angular - the core framework
97%
Total Score
100
97
100
100
0
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-461187 New @angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 20.3.27, 21.0.0 - 21.2.19 and 22.0.0 - 22.0.8. | 0.0.1 - 20.3.2721.0.0 - 21.2.1922.0.0 - 22.0.8 | Medium |
AIKIDO-2026-888246 @angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 20.3.26, 21.0.0 - 21.2.18 and 22.0.0 - 22.0.0. | 0.0.1 - 20.3.2621.0.0 - 21.2.1822.0.0 - 22.0.0 | High |
AIKIDO-2026-618845 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 20.0.0 - 20.3.25, 21.0.0 - 21.2.17 and 22.0.0 - 22.0.4. | 20.0.0 - 20.3.2521.0.0 - 21.2.1722.0.0 - 22.0.4 | Medium |
AIKIDO-2026-657895 @angular/core is vulnerable to Cross-Site Scripting (XSS) in versions 20.0.0 - 20.3.24, 21.0.0 - 21.2.16 and 22.0.0 - 22.0.0. | 20.0.0 - 20.3.2421.0.0 - 21.2.1622.0.0 - 22.0.0 | High |
CVE-2026-50557 @angular/core is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 21.0.0-next.0 - 21.2.15, 22.0.0-next.0 - 22.0.0-rc.2, 20.0.0-next.0 - 20.3.22, 19.0.0-next.0 - 19.2.22 and 0.0.0 - 18.2.14. | 0.0.0 - 18.2.1419.0.0-next.0 - 19.2.2220.0.0-next.0 - 20.3.22 +2 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant