{"id":"GHSA-jrmj-c5cx-3cw6","summary":"Angular has XSS Vulnerability via Unsanitized SVG Script Attributes","details":"A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the `href` and `xlink:href` attributes of SVG `\u003cscript\u003e` elements as a **Resource URL** context.\n\nIn a standard security model, attributes that can load and execute code (like a script's source) should be strictly validated. However, because the compiler does not classify these specific SVG attributes correctly, it allows attackers to bypass Angular's built-in security protections.\n\nWhen template binding is used to assign user-controlled data to these attributes for example, `\u003cscript [attr.href]=\"userInput\"\u003e` the compiler treats the value as a standard string or a non-sensitive URL rather than a resource link. This enables an attacker to provide a malicious payload, such as a `data:text/javascript` URI or a link to an external malicious script.\n\n### Impact\nWhen successfully exploited, this vulnerability allows for **arbitrary JavaScript execution** within the context of the victim's browser session. This can lead to:\n- **Session Hijacking:** Stealing session cookies, localStorage data, or authentication tokens.\n- **Data Exfiltration:** Accessing and transmitting sensitive information displayed within the application.\n- **Unauthorized Actions:** Performing state-changing actions (like clicking buttons or submitting forms) on behalf of the authenticated user.\n\n### Attack Preconditions\n\n1. The victim application must explicitly use SVG `\u003cscript\u003e` elements within its templates.\n2. The application must use property or attribute binding (interpolation) for the `href` or `xlink:href` attributes of those SVG scripts.\n3. The data bound to these attributes must be derived from an untrusted source (e.g., URL parameters, user-submitted database entries, or unsanitized API responses).\n\n### Patches\n- 19.2.18\n- 20.3.16\n- 21.0.7\n- 21.1.0-rc.0\n\n### Workarounds\nUntil the patch is applied, developers should:\n\n- **Avoid Dynamic Bindings**: Do not use Angular template binding (e.g., `[attr.href]`) for SVG `\u003cscript\u003e` elements.\n- **Input Validation**: If dynamic values must be used, strictly validate the input against a strict allowlist of trusted URLs on the server side or before it reaches the template.\n\n### Resources\n\n- https://github.com/angular/angular/pull/66318","aliases":["CVE-2026-22610"],"modified":"2026-08-24T00:36:21.416415668Z","published":"2026-01-09T18:52:14Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-09T18:52:14Z","nvd_published_at":"2026-01-10T04:16:01Z"},"references":[{"type":"WEB","url":"https://github.com/angular/angular/security/advisories/GHSA-jrmj-c5cx-3cw6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22610"},{"type":"WEB","url":"https://github.com/angular/angular/pull/66318"},{"type":"WEB","url":"https://github.com/angular/angular/commit/91dc91bae4a1bbefc58bef6ef739d0e02ab44d56"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-485750.html"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"affected":[{"package":{"name":"@angular/compiler","ecosystem":"npm","purl":"pkg:npm/%40angular/compiler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.1.0-next.0"},{"fixed":"21.1.0-rc.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/core","ecosystem":"npm","purl":"pkg:npm/%40angular/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.1.0-next.0"},{"fixed":"21.1.0-rc.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/compiler","ecosystem":"npm","purl":"pkg:npm/%40angular/compiler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0-next.0"},{"fixed":"21.0.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/core","ecosystem":"npm","purl":"pkg:npm/%40angular/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0-next.0"},{"fixed":"21.0.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/compiler","ecosystem":"npm","purl":"pkg:npm/%40angular/compiler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-next.0"},{"fixed":"20.3.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/core","ecosystem":"npm","purl":"pkg:npm/%40angular/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-next.0"},{"fixed":"20.3.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/compiler","ecosystem":"npm","purl":"pkg:npm/%40angular/compiler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0-next.0"},{"fixed":"19.2.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/core","ecosystem":"npm","purl":"pkg:npm/%40angular/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0-next.0"},{"fixed":"19.2.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/compiler","ecosystem":"npm","purl":"pkg:npm/%40angular/compiler"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"18.2.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}},{"package":{"name":"@angular/core","ecosystem":"npm","purl":"pkg:npm/%40angular/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"18.2.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-jrmj-c5cx-3cw6/GHSA-jrmj-c5cx-3cw6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}