logo

High-Severity Angular XSS Flaw Bypasses Built-In Sanitization

ID: b39cb38d-287e-56c8-8c15-e5412d3fe022

STIX ID: report--b39cb38d-287e-56c8-8c15-e5412d3fe022

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity (CVSS 8.6) Cross-Site Scripting vulnerability (CVE-2026-32635) in Angular’s internationalization (i18n) handling can bypass built-in sanitization when security-sensitive attributes (e.g., `href`, `src`, `action`, `formaction`) are marked with the `i18n-` prefix and bound to unsanitized user input, potentially allowing session hijacking, data exfiltration, and unauthorized actions; Angular has released patches across major versions and recommends immediate updates, using `DomSanitizer`, and avoiding binding untrusted input to internationalized attributes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.