Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS
ID: b32e3b63-8997-5f0b-b8af-b67058d980dd
STIX ID: report--b32e3b63-8997-5f0b-b8af-b67058d980dd
Feed Name: securityonline.info
Threat Score
A high-severity vulnerability (CVE-2026-22610, CVSS 8.5) in the Angular Template Compiler misclassifies SVG <script> href and xlink:href attributes as non-resource URL contexts, allowing attackers to inject arbitrary JavaScript via template bindings (e.g., <script [attr.href]="userInput"). Angular has released patches for multiple versions and advises avoiding dynamic bindings to these attributes or applying strict allowlist validation until systems are updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
