Cross-site scripting in Angular - CVE-2026-22610
Published: January 9, 2026
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of "href" and "xlink:href" attributes of SVG elements in the Angular Template Compiler. A remote user can provide a malicious payload, such as a data:text/javascript URI or a link to an external malicious script and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Sterling Connect:Direct Web Services
Storage Protect Client
Storage Protect for Space Management
How to mitigate CVE-2026-22610
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Storage Protect Client - update to 8.2.2.0
Storage Protect for Space Management - update to 8.2.2.0