Cross-site scripting in Angular - CVE-2026-50557

 

Cross-site scripting in Angular - CVE-2026-50557

Published: September 11, 2026


Vulnerability identifier: #VU149006
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-50557
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript in the target user's browser context.

The vulnerability exists due to improper element sanitization and validation in the Angular template preparser when compiling user-controlled templates with custom namespace prefixes. A remote attacker can inject a namespaced script element to execute arbitrary JavaScript in the target user's browser context.

The application must process user-controlled template input at runtime and must not separately sanitize that input before passing it to the Angular compiler.


Affected software

Angular
webMethods API Gateway
webMethods ControlPlane

How to mitigate CVE-2026-50557

Install security update from vendor's website.

Angular - addressed in versions 19.2.22, 20.3.22, 21.2.15, 22.0.0
webMethods API Gateway - update to 11.1 Fix13
webMethods ControlPlane - update to 11.1 Fix11

External References

Related Security Bulletins