Junglewise Threat Intelligence

CVE-2026-54265: Google Angular XSS via two-way property binding bypass in @angular/compiler

CVE-2026-54265 · Severity: medium · CVSS 3.1 · Published 2026-06-22

Technologies: Google Compiler. Vendors: Angular, Google.

Executive brief

Angular's template compiler fails to sanitize dangerous HTML and URL properties when developers use two-way data binding syntax (instead of one-way binding). This creates a cross-site scripting (XSS) vulnerability where an attacker can inject malicious scripts if the application accepts user input for these sensitive properties. Any Angular application using two-way binding on properties like innerHTML, image src, or link href is at risk of account takeover, data theft, or malware infection.

Technical details

The vulnerability exists in @angular/compiler's template compilation logic for TwoWayProperty operations. When native DOM properties that require sanitization (innerHTML, srcdoc, src, href, data, sandbox) are bound using two-way binding syntax ([(prop)]="value" or bindon-prop="value"), the compiler fails to apply the schema-derived sanitizer resolution that would normally be applied to equivalent one-way bindings. An attacker who can control the value of a two-way-bound sensitive property can bypass Angular's DomSanitizer, enabling XSS execution in the victim's browser. Exploitation requires the application to use two-way binding on a sensitive property and pass user-controlled input without separate manual sanitization. The fix applies proper sanitizer resolution to TwoWayProperty operations during compilation.

Affected products

  • Angular @angular/compiler 20.0.0 to 20.3.24; 21.0.0 to 21.2.16; 22.0.0 to 22.0.0; all versions prior to 20.0.0 through 19.2.25

Timeline

  • 2026-06-15: disclosed: Advisory published; patched versions 22.0.1, 21.2.17, 20.3.25 released

References

Related threats