CVE-2026-69151Patch(angular / angular)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch angular angular systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
angular

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-03: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-03: 108-0308-06
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-031
Patch1
2026-08-061
General1
Full discourse2 posts
  • 0xh3l1x@cgomezz_23
    General

    Well, two high findings on Google :) How exciting! Hehehe https://nvd.nist.gov/vuln/detail/CVE-2026-69151 https://nvd.nist.gov/vuln/detail/CVE-2026-68945 https://t.co/hm3lW7YNL5

    Post summary

    The tweet simply references two high-severity CVEs via NVD links without providing technical information, PoC, exploit code, or evidence of active exploitation.

    00010278
    696 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Multiple High-Severity Vulnerabilities Fixed in Angular Ecosystem Angular released patches addressing three high-severity flaws across its compiler, core, and SSR packages: 1️⃣ CVE-2026-68945 (8.8): SSR HttpTransferCache key collision leading to response reuse & cache poisoning | Affected: @angular/common 2️⃣ CVE-2026-69149 (8.6): SSR XSS via unescaped text nodes in DOM emulation (domino) | Affected: @angular/platform-server 3️⃣ CVE-2026-69151 (7.6): i18n pipeline XSS allowing translation files to inject JS via i18n-on* | Affected: @angular/compiler, @angular/core 👉 Impact: Cross-request state poisoning and arbitrary script execution | Upgrade to Angular 20.3.27, 21.2.19, or 22.0.2

    Post summary

    Angular has released patches for three high‑severity vulnerabilities (CVE-2026‑68945, CVE-2026‑69149, CVE-2026‑69151) and recommends upgrading to specified versions to mitigate XSS and cache poisoning risks.

    00000103
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular-node.js-

Explore more