Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Angular error NG05201 means an untrusted value reached a resource-loading URL, such as an iframe’s src. Find the binding or sanitizer call that supplies it. If the URL is not fully controlled by your application, do not bypass Angular’s check; validate the input or use a regular URL context that Angular can sanitize.

What NG05201 means

Angular distinguishes resource URLs from ordinary links. A regular URL can be sanitized—for example, Angular can remove a dangerous javascript: scheme. A resource URL can make the browser fetch and execute external content, so Angular cannot make an arbitrary string safe and rejects an untrusted value instead. See Angular’s NG05201 error reference.

The error can occur when a value is bound to these resource-loading attributes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • <base href>
  • <embed src>
  • <frame src>
  • <iframe src>
  • <link href>
  • <object codebase> or <object data>

It can also occur when code calls DomSanitizer.sanitize() with SecurityContext.RESOURCE_URL and a plain string. Angular’s reference demonstrates this with an https://example.com string; the URL’s HTTPS scheme does not by itself make the value trusted. See the error reference.

How to find the value that triggers it

  1. Check resource URL bindings. Search templates for the attributes above, particularly bindings such as <iframe [src]="userUrl"></iframe>. Trace the bound value back to where it is created and determine who controls it.
  2. Check explicit sanitization calls. Search application code for DomSanitizer.sanitize() and SecurityContext.RESOURCE_URL. Passing a plain string to that resource URL context can produce NG05201.
  3. Classify the source. A fixed URL selected and controlled by application code is different from a URL supplied by a user, received from an uncontrolled service, or assembled from untrusted input. Do not treat a value as application-controlled merely because it currently looks like a familiar URL.

Choose a safe fix based on who controls the URL

If the URL is user-supplied or otherwise uncontrolled

Do not pass it through bypassSecurityTrustResourceUrl. That method does not sanitize, validate, or restrict a URL; it tells Angular to trust it. Angular warns that trusting a user-supplied resource URL can allow arbitrary content, including malicious scripts, to load. Reject or constrain untrusted input according to the application’s requirements, and use a regular URL binding when the destination belongs in a URL context Angular can sanitize.

If the URL is fully controlled by the application

Angular documents DomSanitizer.bypassSecurityTrustResourceUrl as an escape hatch for a resource URL the application itself controls. It returns a SafeResourceUrl that can be used in a resource URL binding. Use it only after establishing that the value is trusted by design:

import { DomSanitizer, SafeResourceUrl } from '@angular/platform-browser';

const trustedResourceUrl: SafeResourceUrl =
  sanitizer.bypassSecurityTrustResourceUrl('https://example.com/embed');

In this example, sanitizer is an injected DomSanitizer. The trust call is an assertion, not a security check. Do not substitute a value that came from a user or another uncontrolled source. Angular explains this distinction in its NG05201 guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a plain HTTPS URL may still fail

The scheme answers how a URL is addressed; it does not establish that external content is safe to load in a resource context. Angular’s resource URL policy is about the consequences of loading the destination, not just whether the string begins with https://. A plain string therefore remains untrusted in a resource URL context unless the application deliberately marks a controlled value trusted.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Angular version note

Angular’s official NG05201 reference was accessed on October 7, 2026, and its rendered page identifies Angular v22.2.1 build fa63bfa. The page does not state a publication date. Documentation and behavior can change across releases, so consult the error reference for the Angular version used by your application.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.