In a standard security model, attributes that can load and execute code (like a script's source) should be strictly validated. However, because the compiler does not classify these specific SVG attributes correctly, it allows attackers to bypass Angular's built-in security protections.
Stay updated with the latest patches and releases. Plan your sofware desisgn. Avoid common known vulnerabilities fixed by the open source community
Latest patch release: 11.0.9
Latest minor release: 11.2.14
Latest major release: 21.0.8
Maintain your licence declarations and avoid unwanted licences to protect your IP the way you intended.
MIT - MIT License