SecBoard
Zurück zur CVE-Übersicht

CVE-2026-69151

MEDIUM(6.1)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Risk Signal Score15/100 — NIEDRIG
  • CVSS 6.1 — Mittel

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.2%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

6.1

Technische Schwere

Beschreibung

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

Betroffene Produkte

  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*

GitHub Advisories

GHSA-jj27-h5hq-8x99HIGH

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

npm/@angular/compiler22.0.1
GitHub Advisory

Referenzen