| Name | CVE-2025-66412 |
| Description | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| angular.js (PTS) | bullseye | 1.8.2-2 | undetermined |
| bullseye (security) | 1.8.3-1+deb12u1~deb11u1 | undetermined | |
| bookworm | 1.8.3-1 | undetermined | |
| forky, sid, trixie | 1.8.3-3 | undetermined |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| angular.js | source | (unstable) | undetermined |
https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49
https://github.com/angular/angular/commit/1c6b0704fb63d051fab8acff84d076abfbc4893a
check, might not impact the 1.x versions of Angular