Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jrmj-c5cx-3cw6 | Angular has XSS Vulnerability via Unsanitized SVG Script Attributes |
Mon, 23 Feb 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* cpe:2.3:a:angular:angular:21.1.0:next0:*:*:*:node.js:*:* cpe:2.3:a:angular:angular:21.1.0:next1:*:*:*:node.js:*:* cpe:2.3:a:angular:angular:21.1.0:next2:*:*:*:node.js:*:* cpe:2.3:a:angular:angular:21.1.0:next3:*:*:*:node.js:*:* cpe:2.3:a:angular:angular:21.1.0:next4:*:*:*:node.js:*:* |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 14 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 12 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angular
Angular angular |
|
| Vendors & Products |
Angular
Angular angular |
Sat, 10 Jan 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG <script> elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0. | |
| Title | Angular has XSS Vulnerability via Unsanitized SVG Script Attributes | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T15:04:50.480Z
Reserved: 2026-01-07T21:50:39.534Z
Link: CVE-2026-22610
Updated: 2026-01-12T17:29:57.792Z
Status : Analyzed
Published: 2026-01-10T04:16:01.517
Modified: 2026-02-23T18:23:55.623
Link: CVE-2026-22610
OpenCVE Enrichment
Updated: 2026-04-18T19:30:08Z
Github GHSA