logo

High-Severity XSS Flaw in Angular i18n Turns Language Files into Backdoors

ID: 69449035-6446-5194-9b16-0b0fe8a3ca2e

STIX ID: report--69449035-6446-5194-9b16-0b0fe8a3ca2e

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity XSS vulnerability (CVE-2026-27970, CVSS ~7.6) in Angular's i18n pipeline allows attackers to hide JavaScript inside ICU translation files; if translation files are compromised and applications lack strong CSP/Trusted Types, attackers can execute code in users' browsers to steal credentials or alter pages. Angular has released patches (21.2.0, 21.1.6, 20.3.17, 19.2.19) and recommends reviewing third-party translations and enforcing strict CSP as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.