Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16009
CVE-2017-16009
Description
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ag-gridnpm | <= 18.1.3-beta.1 | — |
Affected products
3- HackerOne/ag-grid node modulev5Range: All versions
Patches
Vulnerability mechanics
References
5- spring.io/blog/2016/01/28/angularjs-escaping-the-expression-sandbox-for-xssnvdExploitTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-wfw3-rgfr-6g67ghsaADVISORY
- github.com/ceolter/ag-grid/issues/1287nvdIssue TrackingThird Party AdvisoryWEB
- nodesecurity.io/advisories/327nvdBroken LinkThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-16009ghsaADVISORY
News mentions
0No linked articles in our index yet.