[WID-SEC-2026-2038] Angular: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 22.06.2026 Stand 23.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Angular ist ein TypeScript-basiertes Front-End-Webapplikationsframework. Es ist eine Weiterentwicklung des JavaScript basierten AngularJS. Produkte 22.06.2026 Open Source Angular VSCode Extension <21.2.4 Open Source Angular <22.0.1 Open Source Angular <21.2.17 Open Source Angular <20.3.25 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Angular ausnutzen, um beliebigen Programmcode auszufĂĽhren, um einen Cross-Site Scripting Angriff durchzufĂĽhren, um Informationen offenzulegen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzufĂĽhren. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical set of vulnerabilities in Angular (CVSS Base Score 9.8) allows a remote attacker to execute arbitrary code, conduct XSS attacks, disclose information, bypass security controls, and cause denial of service. Affected versions include the Angular VSCode Extension before 21.2.4, Angular versions before 22.0.1, before 21.2.17, and before 20.3.25. A mitigation is available, though specific patch versions are not detailed in the provided text.