Answer in brief
CVE-2026-69151 records a High severity (CVSS 7.6) vulnerability in Cross-Site Scripting (XSS) via event-handler attributes in Angular i18n. The current sources do not mark it as known exploited. The current feed maps @angular/compiler (npm), @angular/compiler (npm), @angular/compiler (npm), @angular/compiler (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps @angular/compiler (npm), @angular/compiler (npm), @angular/compiler (npm), @angular/compiler (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| @angular/compilernpm | >=22.0.0-next.0,<22.0.1 | 22.0.1 |
| @angular/compilernpm | >=21.0.0-next.0,<21.2.19 | 21.2.19 |
| @angular/compilernpm | >=20.0.0-next.0,<20.3.27 | 20.3.27 |
| @angular/compilernpm | <=19.2.25 | Not reported |
| @angular/compilernpm | >=22.0.0-next.0<22.0.1 | Not reported |
| @angular/compilernpm | >=21.0.0-next.0<21.2.19 | Not reported |
| @angular/compilernpm | >=20.0.0-next.0<20.3.27 | Not reported |
| @angular/corenpm | >=21.0.0-next.0,<21.2.19 | 21.2.19 |
| @angular/corenpm | >=22.0.0-next.0,<22.0.1 | 22.0.1 |
| @angular/corenpm | >=20.0.0-next.0,<20.3.27 | 20.3.27 |
| @angular/corenpm | <=19.2.25 | Not reported |
| @angular/corenpm | >=22.0.0-next.0<22.0.1 | Not reported |
| @angular/corenpm | >=21.0.0-next.0<21.2.19 | Not reported |
| @angular/corenpm | >=20.0.0-next.0<20.3.27 | Not reported |
Published upstream
Jul 29, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Aug 11, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Aug 3, 2026
A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as `onclick` and `onerror` through standard attribute validation (`validateAttribute()` / `validateProperty()`), the i18n metadata collection path allowed these same attribute names to be marked for translation using `i18n-on*` attributes (e.g., `i18n-onerror`). When exploited, a lower-trust translation file could replace a benign static handler such as `onerror="void 0"` with arbitrary executable JavaScript in the localized build. The following example illustrates a vulnerable pattern: ```html <img src="foo.jpg" onerror="void 0" i18n-onerror /> ``` ### Impact When exploited, this vulnerability allows arbitrary JavaScript execution within the context of the vulnerable application's domain if an attacker can control or influence the translation files used during localization. This can lead to: - **Session Hijacking**: Accessing session cookies, tokens, or sensitive user data. - **Unauthorized Actions**: Performing actions on behalf of the authenticated user. ### Patched Versions - 22.0.1 - 21.2.19 - 20.3.27 ### Workarounds Ensure that static event-handler attributes (e.g., `onerror`, `onclick`) are never marked for internationalization (`i18n-on*`) in application templates, and ensure translation files are sourced from trusted origins. ### References - https://github.com/angular/angular/pull/68821 - https://github.com/angular/angular/pull/69306
Quoted source text, attributed separately from HOL analysis.