Back

HIGH

Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

Published Aug 3, 2026

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 3, 2026
Updated Aug 3, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 3, 2026
NVD
Status Analyzed
Modified Aug 11, 2026
Red Hat
Severity Important
Public date Aug 3, 2026
GHSA-JJ27-H5HQ-8X99