AngularJS improperly sanitizes SVG elements
Low severity
GitHub Reviewed
Published
Apr 29, 2025
to the GitHub Advisory Database
•
Updated Apr 30, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2025
Published to the GitHub Advisory Database
Apr 29, 2025
Reviewed
Apr 30, 2025
Last updated
Apr 30, 2025
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '
' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
References