Description
A flaw in AngularJS’ Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim’s browser session.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.2.0-rc.3, <= 1.8.3
References
Could your website be exposed too?
SmartScanner can check your website for Angular's deprecated package has a Cross-Site Scripting issue and gives you actionable findings to investigate.
Start a free scanRelated Issues
- LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution - CVE-2026-42045
- CyberChef has a Cross-site Scripting issue - CVE-2026-42615
- Angular (deprecated package) Cross-site Scripting - CVE-2022-25869
- CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - CVE-2026-28343


