<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – AngularJS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/angularjs.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/angularjs-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – AngularJS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:53 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-41468 – Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41468</guid>
    <pubDate>Wed, 22 Apr 2026 19:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41468</strong></p>
  <p>Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-1104</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10768 – In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10768</guid>
    <pubDate>Tue, 19 Nov 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10768</strong></p>
  <p>In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11354 – The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11354</guid>
    <pubDate>Fri, 19 Apr 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11354</strong></p>
  <p>The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11354">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
