Skip to content

[SEC:HIGH][FP=d236483c] @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers #64

Description

@github-actions

General Information

  • Severity: high
  • Title: @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
  • Category: vulnerabilities
  • Rule: CVE-2026-69151
  • Alert hash: d236483c5919a712e71d5411bb87f5ef
  • First seen: 2026-08-10

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.
(This package is used under: @angular/core@21.2.7)

Location

Dependency Details

  • Package name: @angular/core
  • Installed version: 21.2.7
  • Fixed version: 22.0.1, 21.2.19, 20.3.27
  • Reachable: True

Metadata

Metadata

Labels

scope:securitySecurity, auth, compliancetype:tech-debtMarks task as a tech-debt item

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions