Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-88058: Angular SSR may execute attacker code via raw content

CVE-2026-88058 · published 1 month ago
Summary

When Angular’s server‑side rendering creates certain hidden HTML nodes, it can insert attacker‑supplied text that closes a container tag early, allowing malicious JavaScript to run in users' browsers. This only affects Angular applications using the platform‑server package in versions before the latest updates. Upgrade to the newest Angular release that includes the fix, or avoid creating processing‑instruction nodes with untrusted data.

What to do
  • Update angular platform-server to version 22.1.4.
  • Update angular platform-server to version 21.2.22.
  • Update angular platform-server to version 20.3.30.
  • Update angular @angular/platform-server to version 22.1.4.
  • Update angular @angular/platform-server to version 21.2.22.
  • Update angular @angular/platform-server to version 20.3.30.
Affected software
Ecosystem VendorProductAffected versions
– angular angular <= 19.2.25
>= 19.0.0, <= 19.2.25
>= 20.0.0, < 20.3.30
>= 21.0.0, < 21.2.22
>= 22.0.0, < 22.1.4
Debian:12 debian angular.js All versions
Ubuntu:Pro:16.04:LTS canonical angular.js All versions
npm angular platform-server >= 22.0.0, < 22.1.4
>= 21.0.0, < 21.2.22
>= 20.0.0, < 20.3.30
<= 19.2.25
Fix: upgrade to 22.1.4
npm angular @angular/platform-server >= 22.0.0, < 22.1.4
>= 21.0.0, < 21.2.22
>= 20.0.0, < 20.3.30
<= 19.2.25
Fix: upgrade to 22.1.4
Original advisory text
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes inside fallback raw-content elements without escaping matching ancestor closing tags. ProcessingInstruction data escaped greater-than characters but left less-than characters untouched and did not inspect fallback ancestors, so data such as a matching closing tag prematurely terminates noscript, iframe, noembed, or noframes containers. The vulnerable nodes cannot be authored through standard Angular templates; reachability requires application or library code using inject(DOCUMENT).createProcessingInstruction with attacker-controlled data or Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT parsing, the premature close causes subsequent sibling elements to be interpreted as live HTML and enables arbitrary JavaScript execution in a victim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta