VDB
Sign up
HIGH

GHSA-r3hf-q8q7-fv2p

Angular critical CSS inlining Cross-site Scripting Vulnerability Advisory

Quick fix

GHSA-r3hf-q8q7-fv2p — @nguniversal/common: upgrade to the fixed version with the command below.

npm install @nguniversal/common@16.1.2

Details

### Impact Angular Universal applications on 16.1.0 and 16.1.1 using critical CSS inlining are vulnerable to a [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) attack where an attacker can trick another user into visiting a page which injects malicious JavaScript.

Angular CLI applications without Universal do perform critical CSS inlining as well, however exploiting this requires a malicious actor to already have access to modify source code directly.

### Patches `@nguniversal/common` should be upgraded to 16.1.2 or higher. 16.2.0-rc.0 is safe.

### Workarounds The easiest solution is likely to upgrade Universal to 16.1.2 or downgrade to 16.0.x or lower. Alternatively you can [override](https://docs.npmjs.com/cli/v9/configuring-npm/package-json#overrides) specifically the `critters` dependency with version `0.0.20` in your `package.json`.

```json { "overrides": { "critters": "0.0.20" } } ```

### References

* [Angular Blog Post](https://blog.angular.io/notice-of-xss-issue-affecting-angular-universal-16-1-0-16-1-1-95dbae068f)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@nguniversal/common
Introduced in: 16.1.0Fixed in: 16.1.2
Fixnpm install @nguniversal/common@16.1.2

References