CVE-2026-50557: Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

Published Jun 15, 2026
·
Updated

An issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/validation through specific namespace workarounds.

Specifically, namespaced script elements (e.g., <svg:script> or <:svg:script>) were not properly identified as script elements by the Angular template preparser, allowing them to pass through template compilation without being stripped.

Furthermore, security context schema mappings for element attributes did not consistently handle attributes within namespaced elements (like SVG and MathML), opening up gaps where malicious namespaced attributes could bypass runtime and compile-time sanitizers.

Combined, these flaws enable an attacker who can inject or supply a template/tag structure with custom namespaces to bypass Angular's script-stripping logic and attribute sanitizers, leading to client-side Cross-Site Scripting (XSS).

Impact Any Angular application that compiles user-controlled templates at runtime, or relies on sanitization of namespaced elements/attributes, is vulnerable to this security bypass.

Once exploited, this allows a malicious actor to inject a namespaced script element or dynamic attribute bindings, bypassing core sanitization constraints to execute arbitrary JavaScript within the target user's browser context. This could lead to session hijacking, sensitive data exposure, or unauthorized actions on behalf of the user.

Attack Preconditions To successfully exploit these vulnerabilities, the following environment parameters and application states must all concurrently exist: 1. User-Controlled Template Input: The application must accept user-controlled inputs that are directly processed by the Angular template compiler at runtime. 2. Namespace Parsing Support: The input structure must employ custom namespace prefixes (such as <svg:script>) to evade standard tag-name blocklists/checks. 3. Absence of Additional Context Sanitization: The application does not perform separate input sanitization before feeding values to the Angular compiler.

Patches 22.0.0-rc.2 21.2.15 20.3.22 19.2.23

Other sources

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22, an issue in the @angular/compiler and @angular/core packages allows bypassing element and attribute sanitization/validation through specific namespace workarounds. Specifically, namespaced script elements (e.g., <svg:script> or <:svg:script>) were not properly identified as script elements by the Angular template preparser, allowing them to pass through template compilation without being stripped. Furthermore, security context schema mappings for element attributes did not consistently handle attributes within namespaced elements (like SVG and MathML), opening up gaps where malicious namespaced attributes could bypass runtime and compile-time sanitizers. Combined, these flaws enable an attacker who can inject or supply a template/tag structure with custom namespaces to bypass Angular's script-stripping logic and attribute sanitizers, leading to client-side Cross-Site Scripting (XSS). This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22 and 19.2.22.

MITRE

Affected Software

29 affected componentsFixes available
npm/@angular/compiler<=18.2.14
npm/@angular/compiler>=19.0.0-next.0<19.2.22
19.2.22
npm/@angular/compiler>=20.0.0-next.0<20.3.22
20.3.22
npm/@angular/compiler>=22.0.0-next.0<22.0.0-rc.2
22.0.0-rc.2
npm/@angular/compiler>=21.0.0-next.0<21.2.15
21.2.15
npm/@angular/core<=18.2.14
npm/@angular/core>=19.0.0-next.0<19.2.22
19.2.22
npm/@angular/core>=20.0.0-next.0<20.3.22
20.3.22
npm/@angular/core>=22.0.0-next.0<22.0.0-rc.2
22.0.0-rc.2
npm/@angular/core>=21.0.0-next.0<21.2.15
21.2.15
angular Angular Node.js<=18.2.14
angular Angular Node.js>=19.0.0<19.2.22
angular Angular Node.js>=20.0.0<20.3.22
angular Angular Node.js>=21.0.0<21.2.15
angular Angular Node.js=22.0.0-next0
angular Angular Node.js=22.0.0-next1
angular Angular Node.js=22.0.0-next10
angular Angular Node.js=22.0.0-next11
angular Angular Node.js=22.0.0-next12
angular Angular Node.js=22.0.0-next2
angular Angular Node.js=22.0.0-next3
angular Angular Node.js=22.0.0-next4
angular Angular Node.js=22.0.0-next5
angular Angular Node.js=22.0.0-next6
angular Angular Node.js=22.0.0-next7
angular Angular Node.js=22.0.0-next8
angular Angular Node.js=22.0.0-next9
angular Angular Node.js=22.0.0-rc0
angular Angular Node.js=22.0.0-rc1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 19.2.22
  2. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 20.3.22
  3. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2
  4. Upgrade

    Upgrade npm/@angular/compiler to a version that resolves this vulnerability.

    Fixed in 21.2.15
  5. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 19.2.22
  6. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 20.3.22
  7. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2
  8. Upgrade

    Upgrade npm/@angular/core to a version that resolves this vulnerability.

    Fixed in 21.2.15
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.2.23
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 20.3.22
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 21.2.15
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2

Event History

Jun 15, 2026
Advisory Published
via GitHub·05:21 PM
Data Sourced
via GitHub·05:21 PM
DescriptionWeaknessAffected Software
Jun 22, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-50557?

The severity of CVE-2026-50557 is rated as 56.

2

How do I fix CVE-2026-50557?

To fix CVE-2026-50557, ensure you are using the latest versions of the @angular/compiler and @angular/core packages that address this vulnerability.

3

What type of vulnerability is CVE-2026-50557?

CVE-2026-50557 is categorized as a Cross-Site Scripting (XSS) vulnerability.

4

Which packages are affected by CVE-2026-50557?

The affected packages in CVE-2026-50557 are @angular/compiler and @angular/core.

5

What is the nature of the issue described in CVE-2026-50557?

CVE-2026-50557 allows bypassing element and attribute sanitization through specific namespace workarounds in Angular.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-50557 - Angular: Template and Attribute Namespace Sanitization Bypass (XSS) - SecAlerts