How to use this reference
Treat element identity and output context as part of a binding's security contract. Re-evaluate that contract when composition, inheritance or dynamic construction changes the receiving element. The maintainer lists 22.1.0, 21.2.20 and 20.3.28 as patched; older end-of-support branches receive no patch. The researcher issue distinguishes ordinary URL, resource-loading and HTML contexts, so a generic URL filter is not evidence that all contexts are secured.
Before reading
- Framework component composition and template binding concepts
- Basic browser output-context and sanitization concepts
Context and limits
- Exposure depends on attacker-influenced values reaching affected security-sensitive host bindings and a mismatch between compile-time and concrete-element context. Composition alone does not prove exploitability.
- SkyZeroZx published the linked issue on June 27, 2026; the advisory separately credits that account for remediation. The August 18 date describes the selected maintainer publication, not the earliest public discussion or a product release.
- The maintainer suggests explicit sanitization or safe-scheme restriction as workarounds. Their applicability depends on the actual sink; the reviewed issue identifies stricter resource-loading and HTML contexts. This caveat is editorial defensive guidance, not a claim that the maintainer workaround was independently tested.
- The issue explains a minimal case but links its runnable reproduction elsewhere. No reproduction was run, and observed exploit outcomes are not independently established.
Sources and provenance
- Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler Angular · reviewed 2026-10-03
- ResourceURL sanitizer bypass through host-binding selector mismatch SkyZeroZx · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.