Versions of angular prior to 1.5.0-beta.1 are vulnerable to Cross-Site Scripting. The package fails to sanitize xlink:href attributes, which may allow attackers to execute arbitrary JavaScript in a victim's browser if the value is user-controlled.
Upgrade to version 1.5.0-beta.1 or later.
{
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2020-02-13T17:26:17Z",
"cwe_ids": [
"CWE-79"
],
"nvd_published_at": "2020-01-02T15:15:00Z"
}