CVE-2026-69151

Summary

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

Affected Software

VendorProductVersion RangeStatus
angularangular>= 22.0.0-next.0, < 22.0.1affected
angularangular>= 21.0.0-next.0, < 21.2.19affected
angularangular< 20.3.27affected
@angularcompiler>= 22.0.0-next.0, < 22.0.1affected
@angularcompiler>= 21.0.0-next.0, < 21.2.19affected
@angularcompiler< 20.3.27affected
@angularcore>= 22.0.0-next.0, < 22.0.1affected
@angularcore>= 21.0.0-next.0, < 21.2.19affected
@angularcore< 20.3.27affected

Weaknesses

  • CWE-79: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References