๐Ÿ” CVE Alert

CVE-2026-69151

UNKNOWN 0.0

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

CWE CWE-79
Vendor angular
Product angular
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for angular angular

Be the first to know when new unknown vulnerabilities affecting angular angular are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

angular / angular
>= 22.0.0-next.0, < 22.0.1 >= 21.0.0-next.0, < 21.2.19 < 20.3.27
@angular / compiler
>= 22.0.0-next.0, < 22.0.1 >= 21.0.0-next.0, < 21.2.19 < 20.3.27
@angular / core
>= 22.0.0-next.0, < 22.0.1 >= 21.0.0-next.0, < 21.2.19 < 20.3.27

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99 github.com: https://github.com/angular/angular/pull/68821 github.com: https://github.com/angular/angular/pull/69306 github.com: https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e github.com: https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865