CVE-2026-32635 identifies a high-severity Cross-Site Scripting (XSS) vulnerability within the Angular runtime and compiler, affecting versions prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20. This flaw allows an attacker to inject malicious scripts by bypassing Angular's built-in sanitization when internationalization is enabled for security-sensitive attributes combined with untrusted user-generated data. Rated with a CVSS score of 8.6 (High), exploitation requires user interaction and can lead to high impacts on confidentiality, integrity, and availability via a network attack vector with low complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.0, < 19.2.0CPE matchmatch criteria | cpe:2.3:a:angular:angular_cli:*:*:*:*:*:*:*:* | ||
>= 20.0.0, <= 20.3.18CPE matchmatch criteria | cpe:2.3:a:angular:angular_cli:*:*:*:*:*:*:*:* | ||
>= 21.0.0, < 21.2.4CPE matchmatch criteria | cpe:2.3:a:angular:angular_cli:*:*:*:*:*:*:*:* | ||
22.0.0CPE matchmatch criteria | cpe:2.3:a:angular:angular_cli:22.0.0:next0:*:*:*:*:*:* | ||
22.0.0CPE matchmatch criteria | cpe:2.3:a:angular:angular_cli:22.0.0:next1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.