{"id":"GHSA-r3hf-q8q7-fv2p","summary":"Angular critical CSS inlining Cross-site Scripting Vulnerability Advisory","details":"### Impact\nAngular Universal applications on 16.1.0 and 16.1.1 using critical CSS inlining are vulnerable to a [cross-site scripting (XSS)](https://owasp.org/www-community/attacks/xss/) attack where an attacker can trick another user into visiting a page which injects malicious JavaScript.\n\nAngular CLI applications without Universal do perform critical CSS inlining as well, however exploiting this requires a malicious actor to already have access to modify source code directly.\n\n### Patches\n`@nguniversal/common` should be upgraded to 16.1.2 or higher. 16.2.0-rc.0 is safe.\n\n### Workarounds\nThe easiest solution is likely to upgrade Universal to 16.1.2 or downgrade to 16.0.x or lower. Alternatively you can [override](https://docs.npmjs.com/cli/v9/configuring-npm/package-json#overrides) specifically the `critters` dependency with version `0.0.20` in your `package.json`.\n\n```json\n{\n  \"overrides\": {\n    \"critters\": \"0.0.20\"\n  }\n}\n```\n\n### References\n\n* [Angular Blog Post](https://blog.angular.io/notice-of-xss-issue-affecting-angular-universal-16-1-0-16-1-1-95dbae068f)","modified":"2023-08-09T12:51:51Z","published":"2023-08-09T12:51:51Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-08-09T12:51:51Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/angular/universal/security/advisories/GHSA-r3hf-q8q7-fv2p"},{"type":"PACKAGE","url":"https://github.com/angular/universal"}],"affected":[{"package":{"name":"@nguniversal/common","ecosystem":"npm","purl":"pkg:npm/%40nguniversal/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.1.0"},{"fixed":"16.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-r3hf-q8q7-fv2p/GHSA-r3hf-q8q7-fv2p.json"}}],"schema_version":"1.9.0"}