🔐 CVE Alert

CVE-2026-22610

UNKNOWN 0.0

Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG <script> elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.

CWE CWE-79
Vendor angular
Product angular
Published Jan 10, 2026
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for angular angular

Be the first to know when new unknown vulnerabilities affecting angular angular are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

angular / angular
>= 21.1.0-next.0, < 21.1.0-rc.0 >= 21.0.0-next.0, < 21.0.7 >= 20.0.0-next.0, < 20.3.16 < 19.2.18

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/angular/angular/security/advisories/GHSA-jrmj-c5cx-3cw6 github.com: https://github.com/angular/angular/pull/66318 github.com: https://github.com/angular/angular/commit/91dc91bae4a1bbefc58bef6ef739d0e02ab44d56