Cross-Site Scripting Vulnerability in Angular Server-Side Rendering
A Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.
A Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-69149, affects the @angular/platform-server package, specifically within its integration with the domino DOM emulation library. The issue stems from the improper serialization of fallback raw-content elements, including <iframe>, <noembed>, <noframes>, and <noscript>. When dynamic user-controlled text is bound within these elements, the serializer fails to escape closing tags. During Server-Side Rendering (SSR) post-processing, the unescaped closing tags are rendered into the final HTML output. When a browser subsequently parses this HTML, the injected closing tag causes the browser to terminate the element prematurely, allowing an attacker to inject and execute arbitrary JavaScript within the user's session context. This vulnerability impacts multiple versions of Angular, including those in the 19, 20, 21, and 22 release lines.
Impact
Successful exploitation allows for same-origin XSS attacks against users visiting SSR-rendered applications. Potential impacts include session hijacking, theft of sensitive credentials, unauthorized performative actions on behalf of the user, and website defacement. Organizations using SSR with user-supplied data input in the specified elements are at high risk.
Recommendation
- Update
@angular/platform-serverto the patched versions: 22.0.7, 21.2.19, or 20.3.27, depending on the active release stream. - If patching is not immediately feasible, disable
inlineCriticalstyle optimization inangular.jsonor withinCommonEnginerender options to prevent the vulnerabledominore-serialization process. - Implement strict input sanitization to strip or escape closing tags from any user-controlled data intended for placement inside
<iframe>,<noembed>,<noframes>, or<noscript>elements. - Audit codebase for bindings that place user-supplied content inside these specific raw-content tags.
Immediate actions
Update @angular/platform-server to versions 22.0.7, 21.2.19, or 20.3.27
Mitigations
Disable inlineCritical in angular.json or render options
CVE-2026-69149