Angular vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Jun 18, 2020
to the GitHub Advisory Database
•
Updated Nov 20, 2025
Description
Published by the National Vulnerability Database
Jun 8, 2020
Reviewed
Jun 18, 2020
Published to the GitHub Advisory Database
Jun 18, 2020
Last updated
Nov 20, 2025
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping
<option>elements in<select>ones changes parsing behavior, leading to possibly unsanitizing code.References