Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain
ID: 9328df39-aaa2-5385-bbc7-1201897e28bf
STIX ID: report--9328df39-aaa2-5385-bbc7-1201897e28bf
Feed Name: cybersecurityNews.com
**Angular HttpClient XSRF Token Leakage (CVE-2025-66035)** — A critical vulnerability in Angular's HttpClient incorrectly treats protocol-relative URLs (//example.com) as same-origin, causing the framework to attach users' XSRF tokens to requests sent to external domains. An attacker controlling such a domain could capture tokens and bypass CSRF protections to perform unauthorized actions; developers should upgrade to patched Angular versions or avoid protocol-relative URLs as a workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
