PT-2026-49581 · Google · Angular

·

CVE-2026-54265

·

Published

2026-06-15

·

Updated

2026-06-22

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Angular versions prior to 22.0.1 Angular versions prior to 21.2.17 Angular versions prior to 20.3.25
Description An issue in the @angular/compiler package allows bypassing DOM property sanitization when using two-way property bindings. When a native DOM property requiring sanitization—such as innerHTML, srcdoc, src, href, data, or sandbox—is bound using two-way binding syntax (e.g., [(innerHTML)]="value" or bindon-innerHTML="value"), the template compiler fails to apply the necessary sanitizer resolution to the TwoWayProperty operation. Consequently, these bindings are emitted without the required sanitizer function, unlike one-way bindings which remain protected. This flaw allows an attacker who controls the value of a two-way bound sensitive property to bypass built-in sanitization, potentially leading to client-side Cross-Site Scripting (XSS), where arbitrary JavaScript is executed in the user's browser context.
Recommendations Update to version 22.0.1. Update to version 21.2.17. Update to version 20.3.25. As a temporary workaround, avoid using two-way data binding syntax on security-sensitive native DOM properties such as innerHTML, srcdoc, src, href, data, or sandbox.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54265
GHSA-58W9-8G37-X9V5

Affected Products

Angular