๐Ÿ” CVE Alert

CVE-2025-66412

UNKNOWN 0.0

Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.

CWE CWE-79
Vendor angular
Product angular
Published Dec 1, 2025
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for angular angular

Be the first to know when new unknown vulnerabilities affecting angular angular are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

angular / angular
>= 21.0.0-next.0 < 21.0.2 >= 20.0.0-next.0 < 20.3.15 >= 19.0.0-next.0 < 19.2.17 <= 18.2.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49 github.com: https://github.com/angular/angular/commit/1c6b0704fb63d051fab8acff84d076abfbc4893a cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-485750.html cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-253495.html