vulns.co
/
GKData.io MCP

Angular · 2 min read

Angular host bindings: bind sanitization to the concrete output element

CVE-2026-88057 concerns sanitization chosen from a directive's compile-time selector rather than the concrete element receiving its host binding. Composition and reuse could therefore apply an absent or weaker policy to a more sensitive browser sink. The maintainer confirms browser script-execution risk when an attacker controls the affected bound value; reviewed sources do not establish production compromise.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Treat element identity and output context as part of a binding's security contract. Re-evaluate that contract when composition, inheritance or dynamic construction changes the receiving element. The maintainer lists 22.1.0, 21.2.20 and 20.3.28 as patched; older end-of-support branches receive no patch. The researcher issue distinguishes ordinary URL, resource-loading and HTML contexts, so a generic URL filter is not evidence that all contexts are secured.

Before reading

  • Framework component composition and template binding concepts
  • Basic browser output-context and sanitization concepts

Context and limits

  • Exposure depends on attacker-influenced values reaching affected security-sensitive host bindings and a mismatch between compile-time and concrete-element context. Composition alone does not prove exploitability.
  • SkyZeroZx published the linked issue on June 27, 2026; the advisory separately credits that account for remediation. The August 18 date describes the selected maintainer publication, not the earliest public discussion or a product release.
  • The maintainer suggests explicit sanitization or safe-scheme restriction as workarounds. Their applicability depends on the actual sink; the reviewed issue identifies stricter resource-loading and HTML contexts. This caveat is editorial defensive guidance, not a claim that the maintainer workaround was independently tested.
  • The issue explains a minimal case but links its runnable reproduction elsewhere. No reproduction was run, and observed exploit outcomes are not independently established.

Sources and provenance

  1. Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler Angular · reviewed 2026-10-03
  2. ResourceURL sanitizer bypass through host-binding selector mismatch SkyZeroZx · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software