A critical security vulnerability has been identified in the Angular framework, which could allow attackers to steal sensitive user security tokens.
See also: ASUS warns of critical vulnerability in routers

The vulnerability, recorded as CVE-2025-66035, affects Angular HttpClient and is related to the unintentional leakage of Cross-Site Request Forgery (XSRF) tokens.
Angular applications use a built-in protection mechanism to prevent CSRF attacks. This system works by assigning a secret “token” to a user’s session. Every time the application sends a request to the server, it includes this token to prove that the request is valid.
The problem lies in the way Angular determines whether a request is secure. The mechanism checks URLs to decide whether to attach the secret token. Unfortunately, the system logic incorrectly recognized URLs that start with // (protocol-relative URLs) as “same-origin” or local requests.
See also: Vulnerability in Microsoft Update Health Tools configuration allows RCE

If a developer accidentally uses a URL that does not specify a protocol (e.g., //attacker.com) in an HTTP request, Angular may incorrectly consider it valid and send the user's secret XSRF token to that external domain.
If an attacker manages to trick the application into sending a request to a domain they control, they can capture the user's valid XSRF token. With this token, the attacker can completely bypass CSRF protection and perform unauthorized actions on behalf of the victim, such as changing account settings or submitting fraudulent transactions.
The vulnerability affects multiple versions of Angular. The table below describes the versions affected and the required updates. Development teams using Angular should immediately upgrade to patched versions to ensure the security of their applications.
See also: Vulnerability in HashiCorp Vault allows access to the system without valid credentials

If an immediate upgrade is not possible, there is a workaround: developers should avoid using protocol-less URLs (starting with //). Instead, all requests to the server should use either relative paths (starting with /) or full absolute URLs (starting with https://).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
