VDB
Sign up
MEDIUM5.4

GHSA-mhp6-pxh8-r675

Angular vulnerable to Cross-site Scripting

Quick fix

GHSA-mhp6-pxh8-r675 — angular: upgrade to the fixed version with the command below.

npm install angular@1.8.0

Details

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping `<option>` elements in `<select>` ones changes parsing behavior, leading to possibly unsanitizing code.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular
Introduced in: 0Fixed in: 1.8.0
Fixnpm install angular@1.8.0

References