First published: Tue Apr 29 2025(Updated: )
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Affected Software | Affected Version | How to fix |
---|---|---|
npm/angular | <=1.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-j58c-ww9w-pwp5 is considered high due to its potential to enable content spoofing attacks.
To fix GHSA-j58c-ww9w-pwp5, upgrade AngularJS to version 1.8.4 or later.
GHSA-j58c-ww9w-pwp5 is caused by improper sanitization of the 'href' and 'xlink:href' attributes in '<image>' SVG elements.
Any application using AngularJS versions up to 1.8.3 is affected by GHSA-j58c-ww9w-pwp5.
GHSA-j58c-ww9w-pwp5 can lead to content spoofing attacks, allowing attackers to bypass image source restrictions.