Description
A flaw in AngularJS’ Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim’s browser session.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.2.0-rc.3, <= 1.8.3
References
- GHSA-7x27-g8rg-x87w
- codepen.io
- www.herodevs.com
- access.redhat.com
- bugzilla.redhat.com
- security.access.redhat.com
- CVE-2026-11998
- CWE-79
- CWE-791
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution - CVE-2026-42045
- CyberChef has a Cross-site Scripting issue - CVE-2026-42615
- Angular (deprecated package) Cross-site Scripting - CVE-2022-25869
- CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - CVE-2026-28343
You might also like:
- Tags:
- npm
- angular
Anything's wrong? Let us know Last updated on July 17, 2026


