{"id":"CVE-2025-66412","aliases":["GHSA-v4hv-rgfq-gp49"],"url":"https://o3.security/vulnerability/CVE-2025-66412","summary":"Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes","details":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.","published":"2025-12-01T22:35:59.211Z","modified":"2026-08-12T03:51:42.217805925Z","cvss":null,"epss":{"score":0.00403,"percentile":0.33233,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"21.0.2"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"20.3.15"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"19.2.17"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":null}],"fix":{"url":"https://github.com/angular/angular/commit/1c6b0704fb63d051fab8acff84d076abfbc4893a","label":"angular/angular@1c6b070"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-485750.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66412.json"},{"type":"ADVISORY","url":"https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66412"},{"type":"FIX","url":"https://github.com/angular/angular/commit/1c6b0704fb63d051fab8acff84d076abfbc4893a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.217805925Z"}}