diff --git a/packages/core/src/sanitization/sanitization.ts b/packages/core/src/sanitization/sanitization.ts index 0b2c65ce1679..fb13669155fd 100644 --- a/packages/core/src/sanitization/sanitization.ts +++ b/packages/core/src/sanitization/sanitization.ts @@ -214,7 +214,14 @@ export function ɵɵtrustConstantResourceUrl(url: TemplateStringsArray): Trusted } // Define sets outside the function for O(1) lookups and memory efficiency -const SRC_RESOURCE_TAGS = new Set(['embed', 'frame', 'iframe', 'media', 'script']); +const SRC_RESOURCE_TAGS = new Set([ + 'embed', + 'frame', + 'iframe', + 'media', + 'object', //data attribute + 'script', +]); const HREF_RESOURCE_TAGS = new Set(['base', 'link', 'script']); /**