CVE-2026-27970Disclosure(angular / angular)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch angular angular systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then merging their translations back into the final source code. Translations are frequently handled by contracts with specific partner companies, and involve sending the source messages to a separate contractor before receiving final translations for display to the end user. If the returned translations have malicious content, it could be rendered into the application and execute arbitrary JavaScript. When successfully exploited, this vulnerability allows for execution of attacker controlled JavaScript in the application origin. Depending on the nature of the application being exploited this could lead to credential exfiltration and/or page vandalism. Several preconditions apply to the attack. The attacker must compromise the translation file (xliff, xtb, etc.). Unlike most XSS vulnerabilities, this issue is not exploitable by arbitrary users. An attacker must first compromise an application's translation file before they can escalate privileges into the Angular application client. The victim application must use Angular i18n, use one or more ICU messages, render an ICU message, and not defend against XSS via a safe content security policy. Versions 21.2.0, 21.1.6, 20.3.17, and 19.2.19 patch the issue. Until the patch is applied, developers should consider reviewing and verifying translated content received from untrusted third parties before incorporating it in an Angular application, enabling strict CSP controls to block unauthorized JavaScript from executing on the page, and enabling Trusted Types to enforce proper HTML sanitization.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 2 mentions (2026-02-26); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
angular

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-03-03: 2Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-03: 2Patch / Workaround · 2026-03-04: 2Patch / Workaround · 2026-03-06: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-10: 102-2602-2703-0303-0403-0503-0603-10
Signal classification3 categories
Disclosure
770.0%
Patch
220.0%
General
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure1General1
2026-02-271
Disclosure1
2026-03-032
Disclosure1Patch1
2026-03-042
Disclosure1Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-101
Disclosure1
Full discourse10 posts
  • HeroDevs@herodevs
    Disclosure

    🚨 New CVE Alert: CVE-2026-27970 — High-Severity XSS in Angular i18n A Cross-Site Scripting vulnerability has been identified in Angular’s internationalization (i18n) pipeline, where HTML inside translated ICU messages isn’t properly sanitized — allowing attacker-controlled JavaScript to execute in the application’s origin. This affects versions of @angular/core prior to the latest patched releases (including 19.2.19, 20.3.17, 21.1.6, and 21.2.0). In real-world terms: → If an attacker can compromise a translation file (like .xlf or .xtb), they can inject malicious attributes into ICU messages → When rendered, those attributes may execute arbitrary JavaScript in users’ browsers → This can lead to credential theft, session hijacking, or page manipulation If you’re maintaining Angular apps that use i18n, make sure you’re on a patched version today. And if you’re running Angular versions that have passed official support — or can’t upgrade right away — consider HeroDevs Never-Ending Support (NES) for Angular to receive ongoing security patches and compliance-ready fixes beyond upstream EOL. 🔗 https://www.herodevs.com/support/nes-angular #Angular #CVE #XSS #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs

    Post summary

    A new high-severity XSS vulnerability (CVE-2026-27970) in Angular’s i18n pipeline has been disclosed with detailed exploitation vectors, existing patches, and guidance for updating or using third-party support for older versions.

    00032154
    2.7K followersView on X
  • Dr.Mashari@GMashari
    Disclosure

    📌 ثغرة XSS حرجة في Angular i18n تمكن من تنفيذ تعليمات برمجية خبيثة 🛡️ الفئة: ثغرة 📝 الملخص: تم الكشف عن ثغرة أمنية حرجة من نوع Cross-Site Scripting (XSS)، والمُعرفة بالرمز CVE-2026-27970، ضمن مكونات Angular's internationalization (i18n). تتيح هذه الثغرة ذات الخطورة العالية للمهاجمين تنفيذ تعليمات برمجية خبيثة عن بُعد ضمن سياق تطبيق الضحية، مما قد يؤدي إلى سرقة بيانات حساسة أو التحكم بالمتصفح. تستغل الثغرة عيوبًا في معالجة الإدخالات، ما يمكن المهاجم من حقن نصوص برمجية ضارة. يُنصح بتطبيق التحديثات الأمنية فور توفرها لحماية الأنظمة المتأثرة. 📍 تفاصيل فنية: 🎯 الهدف: التطبيقات التي تستخدم Angular i18n 🧠 التقنية المستخدمة: استغلال ثغرة XSS لتنفيذ تعليمات برمجية 🛑 التوصيات الأمنية: التحديث الفوري لإصدارات Angular المتأثرة 🗓️ تاريخ النشر: 04/03/2026 🔗 للمزيد: https://cybersecuritynews.com/xss-vulnerability-in-angular-i18n/

    Post summary

    The post discloses CVE‑2026‑27970, a high‑severity XSS vulnerability in Angular i18n that allows remote code execution, and recommends applying security updates immediately.

    02010118
    9.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Angular patches a high-severity 7.6 CVSS XSS flaw (CVE-2026-27970). Attackers can weaponize i18n translation files to steal data and hijack user sessions. #Angular #CyberSecurity #XSS #CVE202627970 #WebDev #InfoSec #AppSec #JavaScript #Vulnerability https://securityonline.info/high-severity-xss-flaw-in-angular-i18n-turns-language-files-into-backdoors/

    Post summary

    Angular has released a patch for CVE‑2026‑27970, a high‑severity XSS vulnerability that can be weaponized via i18n translation files to steal data and hijack user sessions.

    00021252
    10.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Angular の脆弱性 CVE-2026-27970 が FIX:i18n に影響を及ぼす JavaScript 実行 https://iototsecnews.jp/2026/03/03/angular-i18n-flaw-lets-hackers-execute-malicious-code-via-critical-xss-vulnerability/ Angular フレームワークにおいて、深刻な脆弱性 CVE-2026-27970 (CVSS 7.6) が発見され、多言語対応 (i18n) の仕組みが悪用される恐れが生じています。この問題の原因は、複雑な翻訳メッセージを扱う ICU メッセージ形式の処理プロセスにおいて、翻訳テキストに含まれる HTML コンテンツのサニタイズ (無害化) が不十分だったことにあります。 通常、Angular アプリの開発では翻訳作業を外部の業者などに依頼し、戻ってきた翻訳ファイルをシステムに組み込みますが、このファイルを侵害できる攻撃者は、悪意の JavaScript を注入できてしまいます。ユーザー入力ではなく、信頼しているはずの翻訳ファイルを起点として、ブラウザ上で不正なコードが実行され、Cookie や ローカル・ストレージに保存される機密情報の窃取などに対するサプライチェーン攻撃を許してしまいます。ご利用のチームは、ご注意ください。 #Angular #CVE202627970 #Vulnerability

    Post summary

    CVE‑2026‑27970 is a high‑severity (CVSS 7.6) XSS vulnerability in Angular’s i18n system that allows attackers to inject malicious JavaScript through compromised translation files, potentially leading to credential theft via cookies or local storage.

    01000123
    484 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Angularのi18n機能にXSSが可能になる危険な脆弱性(CVE-2026-27970) https://rocket-boys.co.jp/security-measures-lab/angular-i18n-xss-vulnerability-cve-2026-27970/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    A new XSS vulnerability in Angular’s i18n feature (CVE-2026-27970) has been disclosed, with the tweet pointing to a detailed security article.

    00000101
    326 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Critical Angular i18n XSS (CVE-2026-27970) Lets Attackers Execute JS via Compromised Translation Files A high-severity XSS flaw in Angular’s i18n/ICU message handling lets attackers run arbitrary JavaScript if they can tamper with translation resources (e.g., XLIFF/XTB), such as via a compromised third-party translation pipeline. Impact includes credential/session theft and full client-side compromise in the app’s origin; affected teams should patch @angular/core to fixed releases and harden with CSP/Trusted Types plus strict translation validation. 🎯 Target: Global/Web Apps (Angular i18n Users) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/xss-vulnerability-in-angular-i18n/

    Post summary

    A high‑severity Angular i18n XSS flaw (CVE‑2026‑27970) permits arbitrary JavaScript execution through tampered translation files; affected teams should apply the fixed @angular/core releases and enforce CSP/Trusted Types.

    0000063
    262 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Severe Angular i18n XSS (CVE-2026-27970) Turns Translation Files Into a Supply-Chain Attack Vector CVE-2026-27970 is a high-severity XSS flaw in Angular i18n where tampered translation files (.xliff/.xtb) can inject JavaScript that executes in users’ browsers, enabling credential/data theft and page manipulation. Patch affected releases (e.g., 19.2.19 / 20.3.17 / 21.1.6 / 21.2.0) and lock down translation workflows with CSP/Trusted Types and strict file vetting. 🎯 Target: Global/Web Applications (Angular) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/severe-xss-vulnerability/

    Post summary

    A high‑severity Angular i18n XSS flaw (CVE‑2026‑27970) allows tampered translation files to inject JavaScript, enabling credential theft and page manipulation. Patches for affected releases are available, and additional mitigations such as CSP and Trusted Types are recommended.

    0000068
    266 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27970: Angular i18n Pipeline: Stored XSS via Malicious ICU Message Attributes A Cross-Site Scripting (XSS) vulnerability exists in the Angular internationalization (i18n) pipeline, specifically within the parsing logic for International Compo... https://cvereports.com/reports/CVE-2026-27970

    Post summary

    The text discloses a stored XSS vulnerability in Angular’s internationalization pipeline caused by malicious ICU message attributes, but provides no proof‑of‑concept, exploit code, or patch information.

    0000052
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27970 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16,… https://www.cve.org/CVERecord?id=CVE-2026-27970

    Post summary

    The text references CVE-2026-27970 and lists affected Angular versions, but provides no PoC, exploit, or patch information.

    0000099
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27970 Cross-Site Scripting in Angular i18n Pipeline Affecting Versions Below 21.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27970

    Post summary

    A Cross‑Site Scripting vulnerability exists in Angular's i18n pipeline affecting versions below 21.2.0, as identified by CVE-2026-27970.

    0000047
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular-node.js-
Appangularangular21.2.0node.js-
Appangularangular21.2.0node.js-
Appangularangular21.2.0node.js-
Appangularangular21.2.0node.js-
Appangularangular21.2.0node.js-

Explore more