General Information
- Severity: high
- Title: @angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers
- Category: vulnerabilities
- Rule: CVE-2026-69151
- Alert hash: d236483c5919a712e71d5411bb87f5ef
- First seen: 2026-08-10
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.
(This package is used under: @angular/core@21.2.7)
Location
Dependency Details
- Package name: @angular/core
- Installed version: 21.2.7
- Fixed version: 22.0.1, 21.2.19, 20.3.27
- Reachable: True
General Information
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.
(This package is used under: @angular/core@21.2.7)
Location
Dependency Details