Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-69151

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

A flaw was found in the Angular compiler's internationalization (i18n) pipeline. This vulnerability allows a lower-trust translation file to replace a static event handler with executable JavaScript. A remote attacker could exploit this by injecting malicious scripts, leading to Cross-Site Scripting (XSS). This could result in unauthorized access to sensitive information or actions performed on behalf of the user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Will not fix
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel8Not affected
Red Hat Ceph Storage 4cephAffected
Red Hat Enterprise Linux 10cephAffected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10intel-cmt-catAffected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 7firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2510726@angular/compiler: @angular/core: Angular: Cross-Site Scripting via internationalization event handlers

EPSS

Процентиль: 10%
0.00199
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
28 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

CVSS3: 6.1
nvd
28 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

CVSS3: 6.1
debian
28 дней назад

Angular is a development platform for building mobile and desktop web ...

github
28 дней назад

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

EPSS

Процентиль: 10%
0.00199
Низкий

8.1 High

CVSS3