There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1995-1 | angular.js security update |
EUVD |
EUVD-2020-0312 | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it. |
Github GHSA |
GHSA-r5fx-8r73-v86c | AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes |
Ubuntu USN |
USN-7958-1 | AngularJS vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angularjs angularjs
|
|
| CPEs | cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Angularjs angular.js
|
Angularjs angularjs
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.196Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14863
No data.
Status : Modified
Published: 2020-01-02T15:15:12.193
Modified: 2025-11-20T18:00:14.787
Link: CVE-2019-14863
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN