CVE-2025-0716

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of  Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.

This issue affects all versions of AngularJS.

Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see  here https://docs.angularjs.org/misc/version-support-status .
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
HeroDevsCNA
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
angular.js
questing
not-affected
plucky
Fixed 1.8.3-1ubuntu0.25.04.1
released
oracular
ignored
noble
Fixed 1.8.3-1ubuntu0.24.04.1
released
jammy
Fixed 1.8.2-2ubuntu0.1
released
focal
Fixed 1.7.9-1ubuntu0.1~esm1
released
bionic
Fixed 1.5.10-1ubuntu0.1~esm1
released
xenial
Fixed 1.2.28-1ubuntu2+esm1
released