Use case · Healthcare ·

An AngularJS patient portal,patched without a rewrite.

Claude Mythos now finds open-source vulnerabilities at machine scale, and end-of-life AngularJS has no one upstream to fix them. Seal, powered by Claude Mythos, does. Below are two copies of the same patient portal: one on public angular 1.8.3, one on Seal's 1.8.3-sp1. Attack both and see what changes.

Powered by Claude Mythos
Live demo

Same portal, same attack. Only the AngularJS build differs.

The attacker controls
What happens
CVE
Public angular 1.8.3 what the portal runs today
Seal angular 1.8.3-sp1 same portal, sealed AngularJS
What the attacker got
From the public portal
  • Nothing yet. Run an attack.
From the Seal portal
  • Nothing yet. Run an attack.
The situation

The portal runs fine. Its framework no longer gets security fixes.

The portal went live on AngularJS in the framework's heyday and has grown feature by feature since. It still works. But AngularJS is end of life, so every newly disclosed CVE stays open on the version the portal ships.

!

Findings that never close

The scanner reports CVEs in angular@1.8.3 every release, including CVE-2024-21490 (CVSS 7.5). NVD's entries say it plainly: the package is end of life and will not receive fixes. There is no upstream version to bump to.

⚕

HIPAA asks for a plan

The Security Rule requires a risk analysis and measures that reduce risks and vulnerabilities to a reasonable level (45 CFR 164.308(a)(1)). HHS's 2025 proposed update would add patch deadlines of 15 days for critical risks and 30 days for high ones. It is still a proposal.

✦

Mythos finds more, faster

Frontier AI now finds open-source vulnerabilities at machine scale: Claude Mythos surfaced 6,200+ high and critical ones across 1,000+ projects. On an end-of-life framework, every new finding is one nobody upstream will fix.

Why the obvious fix doesn't fit

A rewrite closes the CVEs in about three years. The portal is exposed the whole time.

"Upgrade AngularJS" sounds like a version bump. It is not: modern Angular is a different framework with a different component model, so every template, controller, directive and route gets ported. Google's own upgrade guide describes porting components one by one over a period of time, and asks teams to weigh the business case first.

Rewrite in modern AngularSeal angular 1.8.3-sp1
What changes Every screen of the portal, plus a hybrid AngularJS/Angular period with both frameworks in production. One dependency version. Same release, same API, no portal code touched.
Time About 140 weeks for a 100,000-line app at 1,000 lines converted per week. One release cycle: swap the version and run the existing regression suite.
Engineering cost About $2.1M if four engineers sustain that pace for 140 weeks, at a fully loaded median cost. A Seal subscription and one CI run. No roadmap time taken.
CVEs meanwhile The CVEs stay open until the last AngularJS screen is gone. Closed on day one, and new AngularJS CVEs get backported as they are disclosed.

How we estimated it. Rewrite time uses the formula XLTS.dev published for AngularJS migrations: lines of code divided by lines converted per week, times 1.4 (XLTS, "The math of migrating from AngularJS"), with its own worked example of 100,000 lines at 1,000 per week. Cost assumes four engineers at the US median software developer wage of $135,980 (BLS, May 2025), loaded to about $194,000 a year because wages are 70% of total compensation (BLS ECEC, June 2026). Your portal's size, team and rates will differ; the method stays the same.

What Seal shipped Powered by Claude Mythos

Every fix, backported into the release the portal already runs.

Seal backported each fix into AngularJS 1.8.3, rebuilt the package from source and ran the upstream test suite on it. Where a fix would change how working templates behave, we said so and left it out rather than break the portal.

CVEWhat it breaks in a portalSeverityIn 1.8.3-sp1
CVE-2026-11998$sce resource URL allowlist bypassGitHub 7.6Fixed
CVE-2025-0716Unsanitized SVG <image href>Snyk 6.3Fixed
CVE-2024-8372Image allowlist bypass in img[srcset]Snyk 6.3Fixed
CVE-2024-8373Unsanitized source[srcset]Snyk 6.3Fixed
CVE-2024-21490Denial of service through ng-srcsetCVSS 7.5Fixed
CVE-2023-26116Denial of service in angular.copy() (current Chrome sidesteps it; Chrome 143 freezes)CVSS 5.3Fixed
CVE-2023-26118Denial of service in <input type="url">CVSS 5.3Fixed
CVE-2022-25844Denial of service in the currency filter (current Chrome sidesteps it; Chrome 143 freezes)CVSS 5.3Fixed
0lines
Of portal code changed to take the fixes.
7,700+
Upstream AngularJS tests pass on the sealed 1.8.3-sp1 build.
72hours
Patch SLA for critical and high severity CVEs in the packages Seal covers.
SOC 2 Type II
ISO 27001
Seal's own controls, for the auditor who asks who built the patch.
FAQ

Common questions

Get protected

Keep your AngularJS portal. Close its CVEs.

AngularJS no longer gets upstream security patches

Bring the AngularJS release you run and the findings your scanner reports. We will show you which ones a sealed release closes today, and what it takes to put it in your pipeline.

Book a demo Download the PDF