Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-88060: Angular SSR may execute injected JavaScript
CVE-2026-88060 · published 1 month ago
Summary
If you use Angular’s server‑side rendering (the @angular/platform-server package) in versions before the latest releases, it can insert untrusted content into certain HTML tags (like <noscript> or <iframe>) without properly escaping it. This can let an attacker inject code that runs in users’ browsers. Update Angular to version 20.3.30 or later (or 21.2.22 / 22.1.4) to fix the issue.
What to do
- Update angular platform-server to version 22.1.4.
- Update angular platform-server to version 21.2.22.
- Update angular platform-server to version 20.3.30.
- Update angular @angular/platform-server to version 22.1.4.
- Update angular @angular/platform-server to version 21.2.22.
- Update angular @angular/platform-server to version 20.3.30.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | angular | angular |
<= 19.2.25 >= 19.0.0, <= 19.2.25 >= 20.0.0, < 20.3.30 >= 21.0.0, < 21.2.22 >= 22.0.0, < 22.1.4 |
| npm | angular | platform-server |
>= 22.0.0, < 22.1.4 >= 21.0.0, < 21.2.22 >= 20.0.0, < 20.3.30 <= 19.2.25 Fix: upgrade to 22.1.4
|
| npm | angular | @angular/platform-server |
>= 22.0.0, < 22.1.4 >= 21.0.0, < 21.2.22 >= 20.0.0, < 20.3.30 <= 19.2.25 Fix: upgrade to 22.1.4
|
| Debian:12 | debian | angular.js | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | angular.js | All versions |
Original advisory text
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes untrusted input inside template content nested in fallback raw-content elements such as noscript, iframe, noembed, and noframes. The Domino serializer's fallbackRawContentTags traversal stopped at the DocumentFragment used by template.content, so matching closing tags in xmp, style, script, comments, or text nodes were not escaped. Standard interpolation with comments or text nodes is reachable without relaxed schemas; literal xmp or style requires CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM construction is unconditionally affected. When HTML5 RAWTEXT browser parsing encounters the unescaped closing tag, it exits the fallback container and interprets trailing markup as active DOM elements, enabling arbitrary JavaScript execution. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
References
- https://github.com/angular/angular/commit/89b20568dfaee1ec8e0b3bcf1872acdddd2f4f... Patch
- https://github.com/angular/angular/commit/ba3bc47b20b3d12f5eb141ec9c651373ae4d15... Patch
- https://github.com/angular/angular/releases/tag/v21.2.22 Release Notes
- https://github.com/advisories/GHSA-v3p8-whq6-r5jg
- https://github.com/angular/angular Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88060... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-88060 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-88060 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-88060 Third Party Advisory
- https://github.com/angular/angular/commit/73d8bbd27cb46495426d4132975a1355b47ad9... Patch
- https://github.com/angular/domino/commit/04f987dc08ff3736b427f50941adf1722458528... Patch
- https://github.com/angular/angular/releases/tag/v20.3.30 Release Notes
- https://github.com/angular/angular/releases/tag/v22.1.4 Release Notes
- https://github.com/angular/angular/security/advisories/GHSA-v3p8-whq6-r5jg Exploit Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-88060 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
CWE-116Improper Encoding or Escaping of Output
Timeline
Published10 Sep 2026
Updated11 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-88060 · NVD
CVE-2026-88060 · MITRE
GHSA-v3p8-whq6-r5jg · GHSA
GHSA-v3p8-whq6-r5jg · OSV
CVE-2026-88060 · OSV
DEBIAN-CVE-2026-88060 · OSV
UBUNTU-CVE-2026-88060 · OSV
Track software like this
Free during beta