Content Spoofing Vulnerability in AngularJS by Google
CVE-2025-2336
4.8MEDIUM
What is CVE-2025-2336?
A vulnerability in AngularJS's 'ngSanitize' module allows improper sanitization of 'href' and 'xlink:href' attributes in '' SVG elements. This flaw enables attackers to bypass typical image source restrictions, leading to potential content spoofing incidents. Moreover, it can negatively impact the application's performance, as attackers may exploit the vulnerability by using excessively large or slow-loading images. It is important to note that the AngularJS project has reached End-of-Life status and will no longer receive security updates to address this issue.
Affected Version(s)
AngularJS >=1.3.1