StackRadar

CVE-2026-88057

Medium

Advisory

Published 10 Sept 2026In the index since 11 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
2 of 2
affected packages

Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
@angular/compilernpm7.1.4, 12.0.5, 15.0.4, 18.2.3+2 more21.2.206
@angular/corenpm7.1.4, 12.0.5, 15.0.4, 18.2.3+2 more21.2.206
OSV records
GHSA-hh8m-fm6v-7cvg

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
@angular/compiler@19.2.22
@angular/core@19.2.22
no fix listed
no fix listed

Open the chart page →

1,882
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
@angular/compiler@21.2.7
@angular/core@21.2.7
21.2.20
21.2.20

Open the chart page →

3,123
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
glarad/mcp-management-portal-clr:0.6.8807e453354a7
@angular/compiler@18.2.3
@angular/core@18.2.3
no fix listed
no fix listed

Open the chart page →

6,929
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
@angular/compiler@7.1.4
@angular/core@7.1.4
no fix listed
no fix listed

Open the chart page →

3,237
rtlgaloymoney0.4.31 of 2See more

rtl galoymoney 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
@angular/compiler@15.0.4
@angular/core@15.0.4
no fix listed
no fix listed

Open the chart page →

2,090
rtlgaloymoney20.4.31 of 2See more

rtl galoymoney2 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
@angular/compiler@15.0.4
@angular/core@15.0.4
no fix listed
no fix listed

Open the chart page →

2,090
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-88057.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
@angular/compiler@12.0.5
@angular/core@12.0.5
no fix listed
no fix listed

Open the chart page →

5,604

Container images carrying it

6 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
shahanafarooqui/rtl:0.13.3e2195188a451
@angular/compiler@15.0.4
@angular/core@15.0.4
no fix listed
no fix listed
2
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
@angular/compiler@21.2.7
@angular/core@21.2.7
21.2.20
21.2.20
1
glarad/mcp-management-portal-clr:0.6.8807e453354a7
@angular/compiler@18.2.3
@angular/core@18.2.3
no fix listed
no fix listed
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
@angular/compiler@7.1.4
@angular/core@7.1.4
no fix listed
no fix listed
1
lissy93/domain-locker:latestd3c95edc0a8b
@angular/compiler@19.2.22
@angular/core@19.2.22
no fix listed
no fix listed
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
@angular/compiler@12.0.5
@angular/core@12.0.5
no fix listed
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.