9 Total advisories
9 Vulnerabilities
0 Malware
Dependency scanning
Check whether @angular/core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-88057
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
MEDIUM 6.1
CVE-2026-27970
Angular i18n vulnerable to Cross-Site Scripting
MEDIUM 6.1
CVE-2026-54267
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
MEDIUM 6.1
CVE-2026-50557
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
MEDIUM 6.1
CVE-2026-52725
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
UNKNOWN
CVE-2026-22610
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
MEDIUM 5.4
CVE-2021-4231
Angular vulnerable to Cross-site Scripting
UNKNOWN
CVE-2026-69151
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
CRITICAL 9.0
CVE-2026-32635
Angular vulnerable to XSS in i18n attribute bindings
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes