logo

Angular HTTP Client Vulnerability Exposes XSRF Token to an Attacker-Controlled Domain

ID: 9328df39-aaa2-5385-bbc7-1201897e28bf

STIX ID: report--9328df39-aaa2-5385-bbc7-1201897e28bf

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Angular HttpClient XSRF Token Leakage (CVE-2025-66035)** — A critical vulnerability in Angular's HttpClient incorrectly treats protocol-relative URLs (//example.com) as same-origin, causing the framework to attach users' XSRF tokens to requests sent to external domains. An attacker controlling such a domain could capture tokens and bypass CSRF protections to perform unauthorized actions; developers should upgrade to patched Angular versions or avoid protocol-relative URLs as a workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.