GHSA-hh8m-fm6v-7cvg: XSS

Published Sep 10, 2026
·
Updated

Angular automatically sanitizes untrusted values bound to security-sensitive DOM sinks (such as href, src, action, xlink:href, and data) to protect against Cross-Site Scripting (XSS).

Prior to the fix, the Angular compiler determined the SecurityContext for directive host bindings (host: {'[attr.href]': 'value'} or @HostBinding('attr.href')) based solely on the declaring directive or component selector at compile time, rather than the concrete host element that the directive was applied to.

When a directive with a security-sensitive host binding was applied to a different concrete host element—such as through: - hostDirectives composition, - Class inheritance of host bindings, - Dynamic component instantiation (createComponent with custom hostElement or dynamic directives), - Elements with SVG/MathML namespaces (e.g. <svg:a>, <math>), or - Elements using tag-neutral selectors (e.g. :not(...)),

the compiler either failed to associate a sanitizer with the host binding or attached an incorrect security context. As a result, untrusted inputs (e.g. javascript:... URLs) bound via the host binding would be written to the DOM attribute without passing through Angular's built-in sanitizer.

Impact An attacker capable of controlling the value bound to an affected directive host binding could execute arbitrary JavaScript in the user's browser context (Cross-Site Scripting).

Patches This issue has been resolved in versions: - 22.1.0 - 21.2.20 - 20.3.28

Workarounds Ensure that any user-controlled values assigned to properties bound via directive host bindings are explicitly sanitized using DomSanitizer.sanitize(SecurityContext.URL, ...) before assignment, or restrict the input to validated safe URL schemes (e.g. http://, https://).

Affected Software

8 affected componentsFixes available
npm/@angular/compiler<=19.2.25
npm/@angular/core<=19.2.25
npm/@angular/compiler>=20.0.0<20.3.28
20.3.28
npm/@angular/core>=20.0.0<20.3.28
20.3.28
npm/@angular/compiler>=21.0.0<21.2.20
21.2.20
npm/@angular/core>=21.0.0<21.2.20
21.2.20
npm/@angular/compiler>=22.0.0<22.1.0
22.1.0
npm/@angular/core>=22.0.0<22.1.0
22.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 20.3.28
  2. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 20.3.28
  3. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 21.2.20
  4. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 21.2.20
  5. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 22.1.0
  6. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 22.1.0

Event History

Sep 10, 2026
Advisory Published
via GitHub·08:18 PM
Data Sourced
via GitHub·08:18 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications are exposed when a directive or component uses a security-sensitive host binding and is applied to a concrete host element different from the one implied by its selector. Relevant cases include hostDirectives composition, inherited host bindings, dynamic component creation with a custom host element or dynamic directives, SVG or MathML elements, and tag-neutral selectors.

2

What does an attacker need to exploit it?

An attacker needs influence over an untrusted value that is bound through an affected host binding to a security-sensitive attribute such as href, src, action, xlink:href, or data. A value such as a javascript: URL may then be written to the DOM without sanitization.

3

Are ordinary host bindings necessarily affected?

No. The issue occurs when the compiler determines the binding security context from the declaring directive or component selector rather than the concrete host element where the directive is used. Host bindings that remain on the expected concrete host element are not identified by the provided data as affected.

4

How can I identify potentially affected code?

Review directives and components with host bindings such as [attr.href] or @HostBinding('attr.href'), and trace where they are applied. Prioritize bindings involving untrusted input and usages through composition, inheritance, dynamic host elements or directives, SVG/MathML namespaces, and tag-neutral selectors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203