Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
References (4)
Core 4
Core References
Patch x_refsource_misc
https://github.com/angular/angular/commit/1c6b0704fb63d051fab8acff84d076abfbc4893a
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-253495.html
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-485750.html
Vendor Advisory x_refsource_confirm
https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49
Scores
CVSS v3
5.4
EPSS
0.0037
EPSS Percentile
28.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (9)
angular/angular
< 18.2.14
angular/angular
<= 18.2.14
angular/angular
>= 19.0.0-next.0 < 19.2.17
angular/angular
>= 20.0.0-next.0 < 20.3.15
angular/angular
>= 21.0.0-next.0 < 21.0.2
angular/compiler
0 - 18.2.14npm
angular/compiler
19.0.0-next.0 - 19.2.17npm
angular/compiler
20.0.0-next.0 - 20.3.15npm
angular/compiler
21.0.0-next.0 - 21.0.2npm
Published
Dec 01, 2025
Tracked Since
Feb 18, 2026