Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Metrics
Affected Vendors & Products
References
History
Wed, 30 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 29 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status . | |
Title | AngularJS improper sanitization in SVG '<image>' element | |
Weaknesses | CWE-791 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HeroDevs
Published: 2025-04-29T16:26:19.591Z
Updated: 2025-04-29T18:33:37.801Z
Reserved: 2025-01-24T17:15:53.003Z
Link: CVE-2025-0716

Updated: 2025-04-29T18:33:19.527Z

Status : Awaiting Analysis
Published: 2025-04-29T17:15:39.790
Modified: 2025-05-02T13:53:40.163
Link: CVE-2025-0716
