Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-88060: Angular SSR may execute injected JavaScript

CVE-2026-88060 · published 1 month ago
Summary

If you use Angular’s server‑side rendering (the @angular/platform-server package) in versions before the latest releases, it can insert untrusted content into certain HTML tags (like <noscript> or <iframe>) without properly escaping it. This can let an attacker inject code that runs in users’ browsers. Update Angular to version 20.3.30 or later (or 21.2.22 / 22.1.4) to fix the issue.

What to do
  • Update angular platform-server to version 22.1.4.
  • Update angular platform-server to version 21.2.22.
  • Update angular platform-server to version 20.3.30.
  • Update angular @angular/platform-server to version 22.1.4.
  • Update angular @angular/platform-server to version 21.2.22.
  • Update angular @angular/platform-server to version 20.3.30.
Affected software
Ecosystem VendorProductAffected versions
– angular angular <= 19.2.25
>= 19.0.0, <= 19.2.25
>= 20.0.0, < 20.3.30
>= 21.0.0, < 21.2.22
>= 22.0.0, < 22.1.4
npm angular platform-server >= 22.0.0, < 22.1.4
>= 21.0.0, < 21.2.22
>= 20.0.0, < 20.3.30
<= 19.2.25
Fix: upgrade to 22.1.4
npm angular @angular/platform-server >= 22.0.0, < 22.1.4
>= 21.0.0, < 21.2.22
>= 20.0.0, < 20.3.30
<= 19.2.25
Fix: upgrade to 22.1.4
Debian:12 debian angular.js All versions
Ubuntu:Pro:16.04:LTS canonical angular.js All versions
Original advisory text
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes untrusted input inside template content nested in fallback raw-content elements such as noscript, iframe, noembed, and noframes. The Domino serializer's fallbackRawContentTags traversal stopped at the DocumentFragment used by template.content, so matching closing tags in xmp, style, script, comments, or text nodes were not escaped. Standard interpolation with comments or text nodes is reachable without relaxed schemas; literal xmp or style requires CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM construction is unconditionally affected. When HTML5 RAWTEXT browser parsing encounters the unescaped closing tag, it exits the fallback container and interprets trailing markup as active DOM elements, enabling arbitrary JavaScript execution. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta