Vulnerabilities/

Angular's deprecated package has a Cross-Site Scripting issue

Severity:
High

Description

A flaw in AngularJS’ Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim’s browser session.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
angular
Anything's wrong? Let us know Last updated on July 17, 2026