logo

Angular Platform Vulnerability Allows Malicious Code Execution Via Weaponized SVG Animation Files

ID: 0903d5c0-ba1c-5e5f-856d-5f8668150a50

STIX ID: report--0903d5c0-ba1c-5e5f-856d-5f8668150a50

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2025-12-03

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical Stored XSS vulnerability (CVE-2025-66412) in the Angular template compiler can be exploited by binding untrusted data to SVG animation attributeName or URL-holding attributes (e.g., href, xlink:href), allowing JavaScript URL payloads to execute in the application domain; affected Angular releases must be upgraded to 19.2.17, 20.3.15, or 21.0.2 and mitigations (CSP, auditing template bindings) applied until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.