VYPR
Medium severity6.1OSV Advisory· Published Jan 10, 2026· Updated Jun 17, 2026

CVE-2026-22610

CVE-2026-22610

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@angular/compilernpm
>= 21.1.0-next.0, < 21.1.0-rc.021.1.0-rc.0
@angular/corenpm
>= 21.1.0-next.0, < 21.1.0-rc.021.1.0-rc.0
@angular/compilernpm
>= 21.0.0-next.0, < 21.0.721.0.7
@angular/corenpm
>= 21.0.0-next.0, < 21.0.721.0.7
@angular/compilernpm
>= 20.0.0-next.0, < 20.3.1620.3.16
@angular/corenpm
>= 20.0.0-next.0, < 20.3.1620.3.16
@angular/compilernpm
>= 19.0.0-next.0, < 19.2.1819.2.18
@angular/corenpm
>= 19.0.0-next.0, < 19.2.1819.2.18
@angular/compilernpm
<= 18.2.14
@angular/corenpm
<= 18.2.14

Affected products

15

Patches

Vulnerability mechanics

References

7

News mentions

1