CVE-2025-0716

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 791

Summary

CVE-2025-0716 is a vulnerability affecting AngularJS where improper sanitization of 'href' and 'xlink:href' attributes in '<image>' SVG elements allows attackers to bypass image source restrictions, leading to content spoofing. This issue can also negatively impact application performance and behavior by using excessive or slow-to-load images. Sadly, AngularJS, the affected project, is End-of-Life and will not receive updates to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share