CyberRota Analysis
AI-GeneratedThe Angular compiler's i18n pipeline in versions prior to 20.3.27, 21.2.19, and 22.0.1 is vulnerable, allowing lower-trust translation files to replace static event handlers with executable JavaScript, which can lead to potential code execution attacks. This vulnerability poses a significant risk to applications that rely on internationalization features, particularly those handling untrusted translation files. Developers using affected versions should prioritize updating to the patched releases to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)