CVE-2025-66412 - CVE House
Back to Database
Status published High CVE-2025-66412

Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes

Vulnerability Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66412

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

angular
Vulnerable Versions:
>= 21.0.0-next.0 < 21.0.2, >= 20.0.0-next.0 < 20.3.15, >= 19.0.0-next.0 < 19.2.17, <= 18.2.14

Timeline

Official Publish: December 1st, 2025
Last Modified: June 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)