#VU121119 Cross-site scripting in Angular - CVE-2026-22610
Published: January 9, 2026
Angular
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of "href" and "xlink:href" attributes of SVG elements in the Angular Template Compiler. A remote user can provide a malicious payload, such as a data:text/javascript URI or a link to an external malicious script and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.