CVE-2026-50557Disclosure(angular / angular)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/validation through specific namespace workarounds. Specifically, namespaced script elements (e.g., <svg:script> or <:svg:script>) were not properly identified as script elements by the Angular template preparser, allowing them to pass through template compilation without being stripped. Furthermore, security context schema mappings for element attributes did not consistently handle attributes within namespaced elements (like SVG and MathML), opening up gaps where malicious namespaced attributes could bypass runtime and compile-time sanitizers. Combined, these flaws enable an attacker who can inject or supply a template/tag structure with custom namespaces to bypass Angular's script-stripping logic and attribute sanitizers, leading to client-side Cross-Site Scripting (XSS). This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
angular

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-22: 1Technical Details · 2026-06-22: 106-22
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-50557 Cross-Site Scripting via Namespace Bypass in Angular Compiler and Core https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50557

    Post summary

    The passage announces CVE‑2026‑50557 as a cross‑site scripting issue in Angular, but offers no PoC, exploit code, evidence of active exploitation, or patch information.

    0000081
    4.1K followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular-node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-
Appangularangular22.0.0node.js-

Explore more