WhisperX tag archive

#Angular

This page collects WhisperX intelligence signals tagged #Angular. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab · 2026-03-27 17:27:29 · GitHub Issues

1. Angular Compiler 20.3.17 に低深刻度のXSS脆弱性、修正版が公開

Googleが開発する主要なフロントエンドフレームワーク、Angularのコンパイラパッケージに、クロスサイトスクリプティング(XSS)の脆弱性が確認された。脆弱性は `@angular/compiler` のバージョン 20.3.17 に存在し、攻撃者が悪意のあるスクリプトを注入する可能性を開く。セキュリティ企業Snykによる評価では、CVSS v4.0のスコアは2.1で「低」深刻度とされているが、CVSS v3.1では4.4の「中」深刻度と評価されており、リスク評価に差異がある。現時点で、この脆弱性を悪用した攻撃は確認されていない。 この問題は、`@angular/[email protected]` を依存関係として使用してい...

The Lab · 2026-03-27 17:27:30 · GitHub Issues

2. Angular Core 20.3.17 存在跨站脚本 (XSS) 漏洞,官方已发布修复版本

Angular 框架的核心库 `@angular/[email protected]` 版本中被发现存在一个跨站脚本 (XSS) 安全漏洞。该漏洞的 CVSS v3.1 评分为 4.4(中危),而 Snyk 的 CVSS v4.0 评分为 2.1(低危)。目前,该漏洞尚未有已知的公开利用方式,但已确认通过特定路径引入,例如在 `[email protected]` 项目中依赖了受影响的版本。 漏洞的根源在于 `@angular/[email protected]` 版本。Angular 团队已在后续版本中修复了此问题,具体包括 `@angular/[email protected]`、`@20.3.18`、`@21.2.3` 和 `@22.0.0-next.2`...

The Lab · 2026-03-28 09:27:04 · GitHub Issues

3. Critical Node-Forge Vulnerability CVE-2025-12816: ASN.1 Desync Threatens Angular Build Security

A high-severity security flaw in the widely used `node-forge` cryptography library exposes Angular applications to potential cryptographic bypass attacks. The vulnerability, tracked as CVE-2025-12816, is an ASN.1 Validator Desynchronization flaw rated as HIGH severity. It exists in node-forge versions 1.3.1 and below, ...

The Lab · 2026-03-29 05:26:55 · GitHub Issues

4. Angular Compiler Security Update: Critical XSS Vulnerability in SVG Script Handling (CVE-2026-22610)

A critical security vulnerability in the Angular framework's compiler component has been disclosed, prompting an urgent dependency update. The flaw, tracked as CVE-2026-22610 (GHSA-jrmj-c5cx-3cw6), involves a cross-site scripting (XSS) risk stemming from unsanitized SVG script attributes. This vulnerability could allow...

The Lab · 2026-03-29 23:26:54 · GitHub Issues

5. Security Flaw: Angular App Exposes User Session Data via localStorage, High XSS Risk

A critical security vulnerability has been identified in an Angular-based web application, where sensitive user session data is being stored in the browser's localStorage. This implementation flaw, located in the `error.interceptor.ts` file, directly exposes authentication tokens or user identities to any JavaScript co...

The Lab · 2026-04-01 18:27:19 · GitHub Issues

6. Angular SSR v19 Update Patches Critical SSRF Vulnerability (CVE-2026-27739)

A critical security vulnerability in Angular's server-side rendering (SSR) framework has been patched, forcing a major dependency update. The fix, tracked as CVE-2026-27739, addresses a Server-Side Request Forgery (SSRF) flaw in the `@angular/ssr` package. This type of vulnerability allows attackers to trick a server i...

The Lab · 2026-04-01 20:27:27 · GitHub Issues

7. High-Severity CVE-2026-33891 Detected in node-forge-0.10.0, Exposing Angular Build Chain

A high-severity vulnerability, CVE-2026-33891, has been identified in the widely used `node-forge` library version 0.10.0. This JavaScript library provides critical implementations for cryptography, ciphers, and PKI, making its security flaws a significant risk to any dependent application. The vulnerability was detect...

The Lab · 2026-04-01 20:27:37 · GitHub Issues

8. CVE-2026-34043: Medium-Severity Vulnerability Detected in serialize-javascript 6.0.0

A newly disclosed vulnerability, CVE-2026-34043, has been flagged in a widely used JavaScript serialization library. The medium-severity flaw is present in version 6.0.0 of the `serialize-javascript` package, a tool that serializes JavaScript objects to a superset of JSON, including functions and regular expressions. T...

The Lab · 2026-04-07 08:27:00 · GitHub Issues

9. Angular Core v20.3.18 Patches Critical XSS Vulnerability in i18n Attribute Bindings (CVE-2026-32635)

A critical security flaw in the Angular framework has been patched, exposing applications using internationalization (i18n) features to potential cross-site scripting (XSS) attacks. The vulnerability, tracked as CVE-2026-32635 and GHSA-g93w-mfhg-p222, resides within the Angular runtime's handling of i18n attribute bind...

The Lab · 2026-04-07 08:27:01 · GitHub Issues

10. Angular Compiler v20.3.18 Patches Critical XSS Vulnerability in i18n Bindings (CVE-2026-32635)

A critical security flaw in the Angular framework has been patched, exposing applications using internationalization (i18n) to cross-site scripting (XSS) attacks. The vulnerability, tracked as CVE-2026-32635 (GHSA-g93w-mfhg-p222), resides within the `@angular/compiler` package. It specifically affects how Angular handl...

The Lab · 2026-04-07 08:27:02 · GitHub Issues

11. Angular Compiler v21.2.7 Patches Critical XSS Vulnerability in i18n Attribute Bindings (CVE-2026-32635)

A critical security flaw in the Angular framework has been patched, exposing applications using internationalization (i18n) to cross-site scripting (XSS) attacks. The vulnerability, tracked as CVE-2026-32635 and GHSA-g93w-mfhg-p222, was present in the `@angular/compiler` package. This update, moving from version 21.1.3...

The Lab · 2026-04-07 08:27:05 · GitHub Issues

12. Angular Core v20.3.18 Patches Critical XSS Vulnerability in i18n Bindings (CVE-2026-32635)

A critical security flaw in the Angular framework has been patched, exposing applications using internationalization (i18n) to cross-site scripting (XSS) attacks. The vulnerability, tracked as CVE-2026-32635 and GHSA-g93w-mfhg-p222, resides within the Angular runtime's handling of i18n attribute bindings. This specific...

The Lab · 2026-04-07 08:27:06 · GitHub Issues

13. Angular Compiler 20.3.18 Patches Critical XSS Vulnerability in i18n Attribute Bindings

A critical security flaw in the Angular framework's compiler has been patched, exposing applications using internationalization (i18n) to potential cross-site scripting (XSS) attacks. The vulnerability, tracked as CVE-2026-32635 and GHSA-g93w-mfhg-p222, specifically resides in how Angular handles i18n attribute binding...

The Lab · 2026-04-12 11:22:34 · GitHub Issues

15. Angular Compiler Security Alert: Critical XSS Vulnerability in SVG Script Handling (CVE-2026-22610)

A critical security vulnerability has been identified in the Angular compiler, exposing applications to cross-site scripting (XSS) attacks through unsanitized SVG script attributes. The flaw, tracked as CVE-2026-22610 and GHSA-jrmj-c5cx-3cw6, necessitates an immediate dependency update from older versions, such as 14.2...

The Lab · 2026-04-12 11:22:38 · GitHub Issues

16. Angular Core Security Patch: Critical XSS Vulnerability in i18n Module (CVE-2026-27970)

A critical security vulnerability in Angular's internationalization (i18n) module exposes applications to cross-site scripting (XSS) attacks. The flaw, tracked as CVE-2026-27970 and GHSA-prjf-86w9-mfqv, is present in versions prior to 21.2.0 of the @angular/core package. This is not a theoretical risk; the vulnerabilit...

The Lab · 2026-04-12 11:22:39 · GitHub Issues

17. Angular Compiler Security Update: Critical XSS Vulnerability in i18n Attribute Bindings (CVE-2026-32635)

A critical security vulnerability in the Angular framework's compiler component demands immediate attention from development teams. The flaw, tracked as CVE-2026-32635 and GHSA-g93w-mfhg-p222, is a Cross-Site Scripting (XSS) vulnerability specifically located within i18n (internationalization) attribute bindings. This ...

The Lab · 2026-04-18 18:22:38 · GitHub Issues

18. Angular Template Compiler 漏洞 (CVE-2025-66412):存储型 XSS 风险,需紧急更新至 v20.3.18

Angular 框架的核心组件 `@angular/compiler` 中发现一个高危安全漏洞,被标记为 CVE-2025-66412。该漏洞属于存储型跨站脚本攻击(Stored XSS),直接影响 Angular 模板编译器。这意味着攻击者可能通过精心构造的恶意模板,在用户浏览器中执行任意代码,从而窃取用户会话、篡改页面内容或进行其他恶意操作。该漏洞的严重性在于其位于框架的编译层,可能影响所有使用受影响版本构建的 Angular 应用。 漏洞详情显示,问题存在于 `@angular/compiler` 的 20.3.11 及更早版本中。Angular 官方安全团队已发布修复版本 20.3.18。依赖管理工具 Renovate 已...

The Lab · 2026-04-29 07:54:12 · GitHub Issues

19. Angular Production Mode Vulnerability: Researchers Report Click-Triggered XSS via Attribute Bindings Bypasses Security Validation

Security researchers have identified a potential gap in Angular's production-mode security controls that may allow click-triggered cross-site scripting through specific attribute binding syntax. The vulnerability, reported through Angular's official GitHub issue tracker, centers on the interaction between `[attr.onclic...

The Lab · 2026-04-29 08:54:08 · GitHub Issues

20. Angular Server Platform SSRF Guard Found Incomplete After Missing HTTP Absolute-Form Bypass

A security gap in Angular's platform-server package leaves server-side rendering deployments exposed to Server-Side Request Forgery (SSRF) via HTTP absolute-form request targets. The vulnerability exists in the `parseUrl` function within `ServerPlatformLocation`, where a recent patch addressed protocol-relative and bac...