Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g93w-mfhg-p222 | Angular vulnerable to XSS in i18n attribute bindings |
Thu, 30 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angular angular Cli
|
|
| CPEs | cpe:2.3:a:angular:angular_cli:*:*:*:*:*:*:*:* cpe:2.3:a:angular:angular_cli:22.0.0:next0:*:*:*:*:*:* cpe:2.3:a:angular:angular_cli:22.0.0:next1:*:*:*:*:*:* |
|
| Vendors & Products |
Angular angular Cli
|
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 17 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 16 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angular
Angular angular Angular compiler |
|
| Vendors & Products |
Angular
Angular angular Angular compiler |
Fri, 13 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulnerability has been identified in the Angular runtime and compiler. It occurs when the application uses a security-sensitive attribute (for example href on an anchor tag) together with Angular's ability to internationalize attributes. Enabling internationalization for the sensitive attribute by adding i18n-<attribute> name bypasses Angular's built-in sanitization mechanism, which when combined with a data binding to untrusted user-generated data can allow an attacker to inject a malicious script. This vulnerability is fixed in 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20. | |
| Title | Angular has XSS in i18n attribute bindings | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-17T03:55:33.785Z
Reserved: 2026-03-12T15:29:36.559Z
Link: CVE-2026-32635
Updated: 2026-03-16T15:31:34.969Z
Status : Analyzed
Published: 2026-03-16T14:19:40.753
Modified: 2026-04-30T18:23:13.413
Link: CVE-2026-32635
OpenCVE Enrichment
Updated: 2026-03-23T13:39:31Z
Github GHSA