HomeSecurityVulnerability in Angular HTTP Client exposes XSRF token

Vulnerability in Angular HTTP Client exposes XSRF token

A critical security vulnerability has been identified in the Angular framework, which could allow attackers to steal sensitive user security tokens.

See also: ASUS warns of critical vulnerability in routers

Angular vulnerability

The vulnerability, recorded as CVE-2025-66035, affects Angular HttpClient and is related to the unintentional leakage of Cross-Site Request Forgery (XSRF) tokens.

Angular applications use a built-in protection mechanism to prevent CSRF attacks. This system works by assigning a secret “token” to a user’s session. Every time the application sends a request to the server, it includes this token to prove that the request is valid.

The problem lies in the way Angular determines whether a request is secure. The mechanism checks URLs to decide whether to attach the secret token. Unfortunately, the system logic incorrectly recognized URLs that start with // (protocol-relative URLs) as “same-origin” or local requests.

See also: Vulnerability in Microsoft Update Health Tools configuration allows RCE

Vulnerability in Angular HTTP Client exposes XSRF token

If a developer accidentally uses a URL that does not specify a protocol (e.g., //attacker.com) in an HTTP request, Angular may incorrectly consider it valid and send the user's secret XSRF token to that external domain.

If an attacker manages to trick the application into sending a request to a domain they control, they can capture the user's valid XSRF token. With this token, the attacker can completely bypass CSRF protection and perform unauthorized actions on behalf of the victim, such as changing account settings or submitting fraudulent transactions.

The vulnerability affects multiple versions of Angular. The table below describes the versions affected and the required updates. Development teams using Angular should immediately upgrade to patched versions to ensure the security of their applications.

See also: Vulnerability in HashiCorp Vault allows access to the system without valid credentials

Vulnerability in Angular HTTP Client exposes XSRF token

If an immediate upgrade is not possible, there is a workaround: developers should avoid using protocol-less URLs (starting with //). Instead, all requests to the server should use either relative paths (starting with /) or full absolute URLs (starting with https://).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS