CVE-2026-27970: Angular Unvalidated Icu Attributes
HTML attributes parsed from ICU messages without bindings bypass validation and are unconditionally added to the DOM. This can allow attackers to inject malicious attributes (e.g., javascript: URIs) into translations.
Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-27970-angular-unvalidated-icu-attributes --engine opengrepDescription
HTML attributes parsed from ICU messages without bindings bypass validation and are unconditionally added to the DOM. This can allow attackers to inject malicious attributes (e.g., javascript: URIs) into translations.
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0