THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hh8m-fm6v-7cvg (medium) — Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

[GHSA] GHSA-hh8m-fm6v-7cvg (medium) — Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

highgithub_advisoriesPublished 2026-09-10

GHSA-hh8m-fm6v-7cvg Severity: medium CVE: CVE-2026-88057

Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

Angular automatically sanitizes untrusted values bound to security-sensitive DOM sinks (such as `href`, `src`, `action`, `xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).

Prior to the fix, the An

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hh8m-fm6v-7cvg