PT-2025-18187 · Angularjs+3 · Angularjs+3
George Kalpakas
·
Published
2025-04-29
·
Updated
2026-01-14
·
CVE-2025-0716
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
AngularJS versions prior to the end of life, as no specific fixed version is mentioned and the project is End-of-Life.
Description
The issue is related to improper sanitization of the
href and xlink:href attributes in <image> SVG elements, allowing attackers to bypass common image source restrictions. This can lead to Content Spoofing and negatively affect the application's performance and behavior by using too large or slow-to-load images.Recommendations
For all affected versions of AngularJS, consider disabling the use of
<image> SVG elements or restricting the href and xlink:href attributes to mitigate the risk of exploitation, as the project is End-of-Life and will not receive any updates to address this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Angularjs
Debian
Linuxmint
Ubuntu