Description
XSS may be triggered in AngularJS applications that sanitize user-controlled HTML snippets before passing them to JQLite methods like JQLite.prepend, JQLite.after, JQLite.append, JQLite.replaceWith, JQLite.append, new JQLite and angular.element.
Recommendation
Update the angular package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.8.0
- Patched version(s): 1.8.0
References
Could your website be exposed too?
SmartScanner can check your website for XSS via JQLite DOM manipulation functions in AngularJS and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization - Vulnerability
- Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State - CVE-2026-42573
- @tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Ori - Vulnerability


