@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) (CVE-2026-52725)
A vulnerability in the @angular/core package allows attackers to bypass script-execution restrictions during dynamic component creation. Specifically, the createComponent method can mount components directly onto <script> or namespaced script elements, enabling execution of arbitrary JavaScript. This affects Angular applications that use user-controlled inputs for dynamic component instantiation without proper sanitization. Exploitation can lead to client-side Cross-Site Scripting (XSS), potentially resulting in session hijacking or unauthorized actions. Fixed versions include 19.2.23, 20.3.22, 21.2.15, and 22.0.0-rc.2.
AI Analysis
Technical Summary
The vulnerability in @angular/core arises from the dynamic component instantiation mechanism (createComponent) failing to reject mounting components onto <script> or namespaced script elements such as <svg:script>. This allows an attacker controlling the host element or selector parameter to initialize Angular components on script tags, bypassing script-execution restrictions and enabling client-side XSS. The issue requires that the application accepts user-controlled inputs for component creation and does not sanitize these inputs. The flaw is addressed in versions 19.2.23 and later.
Potential Impact
Applications using vulnerable versions of @angular/core that dynamically create components based on user input without sanitization can be exploited to execute arbitrary JavaScript in the user's browser context. This can lead to session hijacking, exposure of sensitive data, or unauthorized actions performed on behalf of the user.
Mitigation Recommendations
Upgrade @angular/core to one of the patched versions: 19.2.23, 20.3.22, 21.2.15, or 22.0.0-rc.2. Ensure that any user-supplied input used as selectors or host elements in dynamic component creation is properly sanitized before use. No other vendor advisories indicate alternative mitigations or that no action is required.
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) (CVE-2026-52725)
Description
A vulnerability in the @angular/core package allows attackers to bypass script-execution restrictions during dynamic component creation. Specifically, the createComponent method can mount components directly onto <script> or namespaced script elements, enabling execution of arbitrary JavaScript. This affects Angular applications that use user-controlled inputs for dynamic component instantiation without proper sanitization. Exploitation can lead to client-side Cross-Site Scripting (XSS), potentially resulting in session hijacking or unauthorized actions. Fixed versions include 19.2.23, 20.3.22, 21.2.15, and 22.0.0-rc.2.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in @angular/core arises from the dynamic component instantiation mechanism (createComponent) failing to reject mounting components onto <script> or namespaced script elements such as <svg:script>. This allows an attacker controlling the host element or selector parameter to initialize Angular components on script tags, bypassing script-execution restrictions and enabling client-side XSS. The issue requires that the application accepts user-controlled inputs for component creation and does not sanitize these inputs. The flaw is addressed in versions 19.2.23 and later.
Potential Impact
Applications using vulnerable versions of @angular/core that dynamically create components based on user input without sanitization can be exploited to execute arbitrary JavaScript in the user's browser context. This can lead to session hijacking, exposure of sensitive data, or unauthorized actions performed on behalf of the user.
Mitigation Recommendations
Upgrade @angular/core to one of the patched versions: 19.2.23, 20.3.22, 21.2.15, or 22.0.0-rc.2. Ensure that any user-supplied input used as selectors or host elements in dynamic component creation is properly sanitized before use. No other vendor advisories indicate alternative mitigations or that no action is required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-692r-grfm-v8x7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-52725"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a58b41268715ace43d68280
Added to database: 07/16/2026, 10:36:02 UTC
Last enriched: 07/16/2026, 10:54:44 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.