Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-88058: Angular SSR may execute attacker code via raw content
CVE-2026-88058 · published 1 month ago
Summary
When Angular’s server‑side rendering creates certain hidden HTML nodes, it can insert attacker‑supplied text that closes a container tag early, allowing malicious JavaScript to run in users' browsers. This only affects Angular applications using the platform‑server package in versions before the latest updates. Upgrade to the newest Angular release that includes the fix, or avoid creating processing‑instruction nodes with untrusted data.
What to do
- Update angular platform-server to version 22.1.4.
- Update angular platform-server to version 21.2.22.
- Update angular platform-server to version 20.3.30.
- Update angular @angular/platform-server to version 22.1.4.
- Update angular @angular/platform-server to version 21.2.22.
- Update angular @angular/platform-server to version 20.3.30.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | angular | angular |
<= 19.2.25 >= 19.0.0, <= 19.2.25 >= 20.0.0, < 20.3.30 >= 21.0.0, < 21.2.22 >= 22.0.0, < 22.1.4 |
| Debian:12 | debian | angular.js | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | angular.js | All versions |
| npm | angular | platform-server |
>= 22.0.0, < 22.1.4 >= 21.0.0, < 21.2.22 >= 20.0.0, < 20.3.30 <= 19.2.25 Fix: upgrade to 22.1.4
|
| npm | angular | @angular/platform-server |
>= 22.0.0, < 22.1.4 >= 21.0.0, < 21.2.22 >= 20.0.0, < 20.3.30 <= 19.2.25 Fix: upgrade to 22.1.4
|
Original advisory text
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes inside fallback raw-content elements without escaping matching ancestor closing tags. ProcessingInstruction data escaped greater-than characters but left less-than characters untouched and did not inspect fallback ancestors, so data such as a matching closing tag prematurely terminates noscript, iframe, noembed, or noframes containers. The vulnerable nodes cannot be authored through standard Angular templates; reachability requires application or library code using inject(DOCUMENT).createProcessingInstruction with attacker-controlled data or Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT parsing, the premature close causes subsequent sibling elements to be interpreted as live HTML and enables arbitrary JavaScript execution in a victim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88058... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-88058
- https://security-tracker.debian.org/tracker/CVE-2026-88058 Vendor Advisory
- https://github.com/angular/angular/issues/70146 Issue Tracking Patch
- https://github.com/angular/angular/commit/73d8bbd27cb46495426d4132975a1355b47ad9... Patch
- https://ubuntu.com/security/CVE-2026-88058 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-88058 Third Party Advisory
- https://github.com/angular/angular/commit/89b20568dfaee1ec8e0b3bcf1872acdddd2f4f... Patch
- https://github.com/angular/angular/commit/ba3bc47b20b3d12f5eb141ec9c651373ae4d15... Patch
- https://github.com/angular/angular/releases/tag/v20.3.30 Release Notes
- https://github.com/angular/domino/commit/04f987dc08ff3736b427f50941adf1722458528... Patch
- https://github.com/angular/angular/releases/tag/v21.2.22 Release Notes
- https://github.com/angular/angular/releases/tag/v22.1.4 Release Notes
- https://github.com/angular/angular/security/advisories/GHSA-j3r3-mxqp-r2p4 Exploit Third Party Advisory
- https://github.com/advisories/GHSA-j3r3-mxqp-r2p4
- https://github.com/angular/angular Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-88058 · NVD
CVE-2026-88058 · MITRE
CVE-2026-88058 · OSV
GHSA-j3r3-mxqp-r2p4 · GHSA
DEBIAN-CVE-2026-88058 · OSV
UBUNTU-CVE-2026-88058 · OSV
GHSA-j3r3-mxqp-r2p4 · OSV
Track software like this
Free during beta