GHSA-jj27-h5hq-8x99

Suggest an improvement
Source
https://github.com/advisories/GHSA-jj27-h5hq-8x99
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jj27-h5hq-8x99
Aliases
Downstream
CGA (2)
Published
2026-08-03T16:23:40Z
Modified
2026-08-03T16:41:11Z
Severity
  • 7.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
Details

A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as onclick and onerror through standard attribute validation (validateAttribute() / validateProperty()), the i18n metadata collection path allowed these same attribute names to be marked for translation using i18n-on* attributes (e.g., i18n-onerror).

When exploited, a lower-trust translation file could replace a benign static handler such as onerror="void 0" with arbitrary executable JavaScript in the localized build.

The following example illustrates a vulnerable pattern:

<img src="foo.jpg" onerror="void 0" i18n-onerror />

Impact

When exploited, this vulnerability allows arbitrary JavaScript execution within the context of the vulnerable application's domain if an attacker can control or influence the translation files used during localization. This can lead to:

  • Session Hijacking: Accessing session cookies, tokens, or sensitive user data.
  • Unauthorized Actions: Performing actions on behalf of the authenticated user.

Patched Versions

  • 22.0.1
  • 21.2.19
  • 20.3.27

Workarounds

Ensure that static event-handler attributes (e.g., onerror, onclick) are never marked for internationalization (i18n-on*) in application templates, and ensure translation files are sourced from trusted origins.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-03T16:23:40Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm
@angular/compiler

Package

Name
@angular/compiler
View open source insights on deps.dev
Purl
pkg:npm/%40angular/compiler

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0-next.0
Fixed
22.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/compiler

Package

Name
@angular/compiler
View open source insights on deps.dev
Purl
pkg:npm/%40angular/compiler

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0-next.0
Fixed
21.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/compiler

Package

Name
@angular/compiler
View open source insights on deps.dev
Purl
pkg:npm/%40angular/compiler

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0-next.0
Fixed
20.3.27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/compiler

Package

Name
@angular/compiler
View open source insights on deps.dev
Purl
pkg:npm/%40angular/compiler

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
19.2.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/core

Package

Name
@angular/core
View open source insights on deps.dev
Purl
pkg:npm/%40angular/core

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0-next.0
Fixed
22.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/core

Package

Name
@angular/core
View open source insights on deps.dev
Purl
pkg:npm/%40angular/core

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0-next.0
Fixed
21.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/core

Package

Name
@angular/core
View open source insights on deps.dev
Purl
pkg:npm/%40angular/core

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0-next.0
Fixed
20.3.27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"
@angular/core

Package

Name
@angular/core
View open source insights on deps.dev
Purl
pkg:npm/%40angular/core

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
19.2.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jj27-h5hq-8x99/GHSA-jj27-h5hq-8x99.json"