Content Spoofing Vulnerability in AngularJS by Google
CVE-2025-2336

4.8MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
4 June 2025

What is CVE-2025-2336?

A vulnerability in AngularJS's 'ngSanitize' module allows improper sanitization of 'href' and 'xlink:href' attributes in '' SVG elements. This flaw enables attackers to bypass typical image source restrictions, leading to potential content spoofing incidents. Moreover, it can negatively impact the application's performance, as attackers may exploit the vulnerability by using excessively large or slow-loading images. It is important to note that the AngularJS project has reached End-of-Life status and will no longer receive security updates to address this issue.

Affected Version(s)

AngularJS >=1.3.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Kalpakas
.
CVE-2025-2336 : Content Spoofing Vulnerability in AngularJS by Google