VDB
Sign up
MEDIUM6.1

GHSA-r5fx-8r73-v86c

AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes

Quick fix

GHSA-r5fx-8r73-v86c — angular: upgrade to the fixed version with the command below.

npm install angular@1.5.0-beta.1

Details

Versions of `angular` prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize `xlink:href` attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.

## Recommendation

Upgrade to version 1.5.0-beta.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular
Introduced in: 0Fixed in: 1.5.0-beta.1
Fixnpm install angular@1.5.0-beta.1

References