THREAT OPS › Threat News › [GHSA] GHSA-hh8m-fm6v-7cvg (medium) — Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
[GHSA] GHSA-hh8m-fm6v-7cvg (medium) — Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
GHSA-hh8m-fm6v-7cvg Severity: medium CVE: CVE-2026-88057
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Angular automatically sanitizes untrusted values bound to security-sensitive DOM sinks (such as `href`, `src`, `action`, `xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).
Prior to the fix, the An
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-88057cve
- http://`url
- https://`url
Original source: https://github.com/advisories/GHSA-hh8m-fm6v-7cvg