PT-2025-18187 · Angularjs+3 · Angularjs+3

George Kalpakas

·

Published

2025-04-29

·

Updated

2026-01-14

·

CVE-2025-0716

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions AngularJS versions prior to the end of life, as no specific fixed version is mentioned and the project is End-of-Life.
Description The issue is related to improper sanitization of the href and xlink:href attributes in <image> SVG elements, allowing attackers to bypass common image source restrictions. This can lead to Content Spoofing and negatively affect the application's performance and behavior by using too large or slow-to-load images.
Recommendations For all affected versions of AngularJS, consider disabling the use of <image> SVG elements or restricting the href and xlink:href attributes to mitigate the risk of exploitation, as the project is End-of-Life and will not receive any updates to address this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-05694
CVE-2025-0716
DLA-4242-1
GHSA-J58C-WW9W-PWP5
USN-7958-1

Affected Products

Angularjs
Debian
Linuxmint
Ubuntu