GHSA-jj27-h5hq-8x99
HIGHCVE-2026-69151A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as onclick and onerror through standard attribute validation (validateAttribute() / validateProperty()), the i18n metadata collection path allowed these same attribute names to be marked for translation us
- Affected
- >=22.0.0-next.0, <22.0.1, >= 22.0.0-next.0, < 22.0.1
- Fixed in
- 22.0.1
- Weakness
- CWE-79
- Published
- 2026-08-03
- Source
- osv