Cross-site scripting in Angular - CVE-2026-52725
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a target user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Angular template preparser when compiling user-controlled templates containing custom namespace prefixes. A remote attacker can inject a namespaced script element to execute arbitrary JavaScript in a target user's browser.
Exploitation requires an application to compile user-controlled templates at runtime without separate input sanitization.