logo

Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS

ID: b32e3b63-8997-5f0b-b8af-b67058d980dd

STIX ID: report--b32e3b63-8997-5f0b-b8af-b67058d980dd

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-22610, CVSS 8.5) in the Angular Template Compiler misclassifies SVG <script> href and xlink:href attributes as non-resource URL contexts, allowing attackers to inject arbitrary JavaScript via template bindings (e.g., <script [attr.href]="userInput"). Angular has released patches for multiple versions and advises avoiding dynamic bindings to these attributes or applying strict allowlist validation until systems are updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.