CVE-2025-66412

MEDIUM

Angular <21.0.2,20.3.15,19.2.17 - XSS

Title source: llm
STIX 2.1

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.

Scores

CVSS v3 5.4
EPSS 0.0037
EPSS Percentile 28.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (9)
angular/angular < 18.2.14
angular/angular <= 18.2.14
angular/angular >= 19.0.0-next.0 < 19.2.17
angular/angular >= 20.0.0-next.0 < 20.3.15
angular/angular >= 21.0.0-next.0 < 21.0.2
angular/compiler 0 - 18.2.14npm
angular/compiler 19.0.0-next.0 - 19.2.17npm
angular/compiler 20.0.0-next.0 - 20.3.15npm
angular/compiler 21.0.0-next.0 - 21.0.2npm
Published Dec 01, 2025
Tracked Since Feb 18, 2026