logo

Critical XSS Vulnerability in Angular i18n Enables Malicious Code Execution

ID: 26ef80c1-8e51-5a5a-9ce9-ab5d88532636

STIX ID: report--26ef80c1-8e51-5a5a-9ce9-ab5d88532636

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

A high-severity XSS vulnerability (CVE-2026-27970) was found in Angular's i18n message handling that can execute arbitrary JavaScript if an attacker can modify application translation files; multiple @angular/core versions are affected, developers are urged to apply published patches or mitigations (strict CSP, Trusted Types, translation validation) to prevent credential theft and page manipulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.