Angular Platform Vulnerability Allows Malicious Code Execution Via Weaponized SVG Animation Files
ID: 0903d5c0-ba1c-5e5f-856d-5f8668150a50
STIX ID: report--0903d5c0-ba1c-5e5f-856d-5f8668150a50
Feed Name: cybersecurityNews.com
Threat Score
A critical Stored XSS vulnerability (CVE-2025-66412) in the Angular template compiler can be exploited by binding untrusted data to SVG animation attributeName or URL-holding attributes (e.g., href, xlink:href), allowing JavaScript URL payloads to execute in the application domain; affected Angular releases must be upgraded to 19.2.17, 20.3.15, or 21.0.2 and mitigations (CSP, auditing template bindings) applied until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
