-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper input sanitization during paste operations. textAngular's content processing pipeline: 1) taBind.unwrap handles HTML normalization during paste events but doesn't remove event handlers. 2) taSanitize, responsible for cleaning HTML, uses an insufficient allowlist that permits dangerous attributes. This matches the PoC where <img> tags with onload/onerror events bypass sanitization. The functions are core to HTML processing in vulnerable versions, and their lack of proper attribute filtering directly enables the XSS vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| textangular | npm | <= 1.5.16 |
KEV Misses 88% of Exploited CVEs- Get the report