Looking for the vulnerability index of Invicti's legacy products?
Angular : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vuln (CVE-2026-88057) - Vulnerability Database

Angular : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vuln (CVE-2026-88057)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect sanitizer for security-sensitive directive host bindings because SecurityContext was derived from the declaring directive or component selector rather than the concrete host element. The mismatch is reachable through hostDire

References