{"id":"CVE-2026-22610","aliases":["GHSA-jrmj-c5cx-3cw6"],"url":"https://o3.security/vulnerability/CVE-2026-22610","summary":"Angular has XSS Vulnerability via Unsanitized SVG Script Attributes","details":"A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the `href` and `xlink:href` attributes of SVG `<script>` elements as a **Resource URL** context.\n\nIn a standard security model, attributes that can load and execute code (like a script's source) should be strictly validated. However, because the compiler does not classify these specific SVG attributes correctly, it allows attackers to bypass Angular's built-in security protections.\n\nWhen template binding is used to assign user-controlled data to these attributes for example, `<script [attr.href]=\"userInput\">` the compiler treats the value as a standard string or a non-sensitive URL rather than a resource link. This enables an attacker to provide a malicious payload, such as a `data:text/javascript` URI or a link to an external malicious script.\n\n### Impact\nWhen successfully exploited, this vulnerability allows for **arbitrary JavaScript execution** within the context of the victim's browser session. This can lead to:\n- **Session Hijacking:** Stealing session cookies, localStorage data, or authentication tokens.\n- **Data Exfiltration:** Accessing and transmitting sensitive information displayed within the application.\n- **Unauthorized Actions:** Performing state-changing actions (like clicking buttons or submitting forms) on behalf of the authenticated user.\n\n### Attack Preconditions\n\n1. The victim application must explicitly use SVG `<script>` elements within its templates.\n2. The application must use property or attribute binding (interpolation) for the `href` or `xlink:href` attributes of those SVG scripts.\n3. The data bound to these attributes must be derived from an untrusted source (e.g., URL parameters, user-submitted database entries, or unsanitized API responses).\n\n### Patches\n- 19.2.18\n- 20.3.16\n- 21.0.7\n- 21.1.0-rc.0\n\n### Workarounds\nUntil the patch is applied, developers should:\n\n- **Avoid Dynamic Bindings**: Do not use Angular template binding (e.g., `[attr.href]`) for SVG `<script>` elements.\n- **Input Validation**: If dynamic values must be used, strictly validate the input against a strict allowlist of trusted URLs on the server side or before it reaches the template.\n\n### Resources\n\n- https://github.com/angular/angular/pull/66318","published":"2026-01-10T03:35:40.727Z","modified":"2026-08-12T03:51:13.837530563Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"21.1.0-rc.0"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"21.1.0-rc.0"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"21.0.7"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"21.0.7"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"20.3.16"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"20.3.16"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":"19.2.18"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"19.2.18"},{"ecosystem":"npm","name":"@angular/compiler","fixedVersion":null},{"ecosystem":"npm","name":"@angular/core","fixedVersion":null}],"fix":{"url":"https://github.com/angular/angular/commit/91dc91bae4a1bbefc58bef6ef739d0e02ab44d56","label":"angular/angular@91dc91b"},"references":[{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-485750.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22610.json"},{"type":"ADVISORY","url":"https://github.com/angular/angular/security/advisories/GHSA-jrmj-c5cx-3cw6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22610"},{"type":"FIX","url":"https://github.com/angular/angular/commit/91dc91bae4a1bbefc58bef6ef739d0e02ab44d56"},{"type":"FIX","url":"https://github.com/angular/angular/pull/66318"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.837530563Z"}}