{"id":"CVE-2026-52725","aliases":["GHSA-692r-grfm-v8x7"],"url":"https://o3.security/vulnerability/CVE-2026-52725","summary":"Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)","details":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/core package allows bypassing script-execution restrictions during dynamic component creation. Specifically, the dynamic component instantiation mechanism (createComponent) failed to reject mounting components directly onto a <script> or namespaced script element (such as <svg:script>). This enabled the initialization of custom components on a tag that executes scripts, allowing attackers to hijack or inject script-executing hosts. This flaw enables an attacker who can control the host element or selector parameter passed to createComponent to initialize or mount an Angular component directly onto a <script> tag, leading to execution of untrusted code or client-side Cross-Site Scripting (XSS). This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.","published":"2026-06-22T15:18:43.036Z","modified":"2026-08-12T03:51:38.927747875Z","cvss":null,"epss":{"score":0.00398,"percentile":0.32852,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@angular/core","fixedVersion":"21.2.15"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"22.0.0-rc.2"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"19.2.23"},{"ecosystem":"npm","name":"@angular/core","fixedVersion":null},{"ecosystem":"npm","name":"@angular/core","fixedVersion":"20.3.22"}],"fix":{"url":"https://github.com/angular/angular/pull/68686","label":"angular/angular#68686"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/52xxx/CVE-2026-52725.json"},{"type":"ADVISORY","url":"https://github.com/angular/angular/security/advisories/GHSA-692r-grfm-v8x7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52725"},{"type":"FIX","url":"https://github.com/angular/angular/pull/68686"},{"type":"FIX","url":"https://github.com/angular/angular/pull/68713"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.927747875Z"}}