Executive brief
A security flaw has been identified in AngularJS, a widely used framework for building web applications. The vulnerability exists in the component responsible for ensuring that only safe web addresses (URLs) are used for loading scripts and content. An attacker could exploit this to run malicious code in a user's browser, potentially leading to the theft of sensitive session information or unauthorized actions on behalf of the user.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the AngularJS Strict Contextual Escaping (SCE) module. The root cause is a flaw in the logic used to validate resource URLs against regular expression matchers, which can result in partial matches. This allows an attacker to bypass security policies and inject unsafe values into sensitive contexts such as script tags, iframes, or route templates. Exploitation requires a victim to interact with a malicious link or page. As the AngularJS project is End-of-Life (EOL), no official patches will be released.
Affected products
- AngularJS angular >= 1.2.0-rc.3, <= 1.8.3
Timeline
- 2026-06-24: disclosed: NVD publication date
- 2026-06-24: advisory: GitHub Advisory published
- 2026-07-17: other: Advisory updated and reviewed
References
- https://api.github.com/users/spectacularpigeoncow
- https://github.com/spectacularpigeoncow
- https://api.github.com/users/spectacularpigeoncow/gists%7B/gist_id%7D
- https://api.github.com/users/spectacularpigeoncow/repos
- https://avatars.githubusercontent.com/u/113363362?v=4
- https://api.github.com/users/spectacularpigeoncow/events%7B/privacy%7D