Medium [CVE-2026-52725] @angular/core: @angular/core: Cross-Site Scripting (XSS) via dynamic component creation bypass
This medium-severity Red Hat Linux advisory covers CVE-2026-52725 affecting Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Fuse 7.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/core package allows bypassing script-execution restrictions during dynamic component creation.
Specifically, the dynamic component instantiation mechanism (createComponent) failed to reject mounting components directly onto a
Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Fuse 7.
- < 22.0.0-rc
- < 21.2.15
- < 20.3.22
- < 19.2.23
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
- 22.0.0
- 21.2.15
- 20.3.22
- 19.2.23
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Mitigation checklist
- Users of applications built with @angular/core versions prior to 19.2.23, 20.3.22, 21.2.15, or 22.0.0-rc.2 should upgrade to the fixed versions. Applications that do not use the createComponent API with user-controlled host element parameters are not exploitable.
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.