Claude Mythos now finds open-source vulnerabilities at machine scale, and end-of-life AngularJS
has no one upstream to fix them. Seal, powered by Claude Mythos, does. Below are two copies of
the same patient portal: one on public angular 1.8.3, one on Seal's 1.8.3-sp1.
Attack both and see what changes.
angular 1.8.3 what the portal runs todayangular 1.8.3-sp1 same portal, sealed AngularJSThe portal went live on AngularJS in the framework's heyday and has grown feature by feature since. It still works. But AngularJS is end of life, so every newly disclosed CVE stays open on the version the portal ships.
The scanner reports CVEs in angular@1.8.3 every release, including
CVE-2024-21490 (CVSS 7.5). NVD's entries say it plainly: the package is
end of life and will not receive fixes. There is no upstream version to bump to.
The Security Rule requires a risk analysis and measures that reduce risks and vulnerabilities to a reasonable level (45 CFR 164.308(a)(1)). HHS's 2025 proposed update would add patch deadlines of 15 days for critical risks and 30 days for high ones. It is still a proposal.
Frontier AI now finds open-source vulnerabilities at machine scale: Claude Mythos surfaced 6,200+ high and critical ones across 1,000+ projects. On an end-of-life framework, every new finding is one nobody upstream will fix.
"Upgrade AngularJS" sounds like a version bump. It is not: modern Angular is a different framework with a different component model, so every template, controller, directive and route gets ported. Google's own upgrade guide describes porting components one by one over a period of time, and asks teams to weigh the business case first.
| Rewrite in modern Angular | Seal angular 1.8.3-sp1 | |
|---|---|---|
| What changes | Every screen of the portal, plus a hybrid AngularJS/Angular period with both frameworks in production. | One dependency version. Same release, same API, no portal code touched. |
| Time | About 140 weeks for a 100,000-line app at 1,000 lines converted per week. | One release cycle: swap the version and run the existing regression suite. |
| Engineering cost | About $2.1M if four engineers sustain that pace for 140 weeks, at a fully loaded median cost. | A Seal subscription and one CI run. No roadmap time taken. |
| CVEs meanwhile | The CVEs stay open until the last AngularJS screen is gone. | Closed on day one, and new AngularJS CVEs get backported as they are disclosed. |
How we estimated it. Rewrite time uses the formula XLTS.dev published for AngularJS migrations: lines of code divided by lines converted per week, times 1.4 (XLTS, "The math of migrating from AngularJS"), with its own worked example of 100,000 lines at 1,000 per week. Cost assumes four engineers at the US median software developer wage of $135,980 (BLS, May 2025), loaded to about $194,000 a year because wages are 70% of total compensation (BLS ECEC, June 2026). Your portal's size, team and rates will differ; the method stays the same.
Seal backported each fix into AngularJS 1.8.3, rebuilt the package from source and ran the upstream test suite on it. Where a fix would change how working templates behave, we said so and left it out rather than break the portal.
| CVE | What it breaks in a portal | Severity | In 1.8.3-sp1 |
|---|---|---|---|
| CVE-2026-11998 | $sce resource URL allowlist bypass | GitHub 7.6 | Fixed |
| CVE-2025-0716 | Unsanitized SVG <image href> | Snyk 6.3 | Fixed |
| CVE-2024-8372 | Image allowlist bypass in img[srcset] | Snyk 6.3 | Fixed |
| CVE-2024-8373 | Unsanitized source[srcset] | Snyk 6.3 | Fixed |
| CVE-2024-21490 | Denial of service through ng-srcset | CVSS 7.5 | Fixed |
| CVE-2023-26116 | Denial of service in angular.copy() (current Chrome sidesteps it; Chrome 143 freezes) | CVSS 5.3 | Fixed |
| CVE-2023-26118 | Denial of service in <input type="url"> | CVSS 5.3 | Fixed |
| CVE-2022-25844 | Denial of service in the currency filter (current Chrome sidesteps it; Chrome 143 freezes) | CVSS 5.3 | Fixed |
No rewrite, no hybrid ngUpgrade period, no new component model. The portal's templates, controllers and directives stay exactly as they are.
Run seal fix in CI, or pin angular 1.8.3-sp1 from the Seal Artifact Server, directly or through Artifactory or Nexus. Seal also publishes sealed 1.8.0 and 1.8.2 builds for portals pinned to those releases.
Each fix is a small, reviewable patch with its own regression test. Your regression suite runs against the same API, and the scanner stops flagging them.
No. Google ended long-term support for AngularJS. The npm packages stay published but deprecated, and no new upstream 1.x releases ship, so newly disclosed CVEs have no upstream fix.
Modern Angular is a different framework, so in practice every screen is rewritten. Google's upgrade guide describes porting AngularJS components one by one with ngUpgrade over a period of time, running both frameworks side by side until the last component is ported.
The fixes change 110 lines of AngularJS source and keep the public API. The upstream test suite, more than 7,700 tests, passes on the sealed build. The one fix that would change working templates, CVE-2022-25869, is left out and documented instead of shipped.
No single product does. Sealed releases give you a remediation you can apply and document for known AngularJS CVEs, which is evidence for the risk management your Security Rule program already requires. Your compliance team decides how it fits your controls.
Seal covers the open-source packages under the portal too: the npm tree in the front end, the back-end ecosystems behind it, and the Linux base images it runs on. seal scan shows what is open and what a sealed version closes.
Bring the AngularJS release you run and the findings your scanner reports. We will show you which ones a sealed release closes today, and what it takes to put it in your pipeline.