GHSA-7x27-g8rg-x87w

Suggest an improvement
Source
https://github.com/advisories/GHSA-7x27-g8rg-x87w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7x27-g8rg-x87w/GHSA-7x27-g8rg-x87w.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-7x27-g8rg-x87w
Aliases
Downstream
CGA (16)
Published
2026-06-24T21:30:44Z
Modified
2026-07-19T07:37:21Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Angular's deprecated package has a Cross-Site Scripting issue
Details

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.

SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-791"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-17T21:47:00Z",
    "nvd_published_at": "2026-06-24T21:16:52Z",
    "severity": "HIGH"
}
References

Affected packages

npm / angular

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.2.0-rc.3
Last Affected
1.8.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7x27-g8rg-x87w/GHSA-7x27-g8rg-x87w.json"