💡 XSS in i18n attribute bindings
A high-severity XSS security issue affecting i18n attribute bindings has been identified in Angular.
💡 XSS in i18n attribute bindings
A high-severity XSS security issue affecting i18n attribute bindings has been identified in Angular.
This lets you fully configure how HTML strings are cleaned as they're parsed.
hacks.mozilla.org/2026/02/good...
This lets you fully configure how HTML strings are cleaned as they're parsed.
hacks.mozilla.org/2026/02/good...
twexit.nl/makepretty.p...
twexit.nl/makepretty.p...
Works on every browser
Works on every browser
11 char XSS with mind-boggling race-conditions.
TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)
It's shorter than location=name !!
terjanq.me/solutions/jo...
11 char XSS with mind-boggling race-conditions.
TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)
It's shorter than location=name !!
terjanq.me/solutions/jo...
The vulnerability affects applications that iterate over all search parameters inside a server `load` function. More details in the advisory 👇
The vulnerability affects applications that iterate over all search parameters inside a server `load` function. More details in the advisory 👇
That's probably still possible but since I'm not getting paid... 🤷🏻♀️
That's probably still possible but since I'm not getting paid... 🤷🏻♀️