{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agoogleangular/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:google:angular:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-88060"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Angular platform-server (\u003e= 22.0.0, \u003c 22.1.4)","Angular platform-server (\u003e= 21.0.0, \u003c 21.2.22)","Angular platform-server (\u003e= 20.0.0, \u003c 20.3.30)","Angular platform-server (\u003c= 19.2.25)","Angular platform-server (22.0.0 \u003c= version \u003c 22.1.4)","Angular platform-server (21.0.0 \u003c= version \u003c 21.2.22)","Angular platform-server (20.0.0 \u003c= version \u003c 20.3.30)"],"_cs_severities":["high"],"_cs_tags":["ssrf","angular","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eA high-severity Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-88060, affects the \u003ccode\u003e@angular/platform-server\u003c/code\u003e package used for server-side rendering (SSR). The flaw occurs because the HTML serializer fails to correctly identify and escape closing tags when processing \u003ccode\u003e\u0026lt;template\u0026gt;\u003c/code\u003e content that resides within fallback raw-content elements, such as \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;noembed\u0026gt;\u003c/code\u003e, or \u003ccode\u003e\u0026lt;noframes\u0026gt;\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIn HTML5, these elements place the browser in \u003ccode\u003eRAWTEXT\u003c/code\u003e mode, where internal content is parsed as literal text until a matching closing tag is encountered. Because Angular's serializer treats the contents of a \u003ccode\u003e\u0026lt;template\u0026gt;\u003c/code\u003e as a separate \u003ccode\u003eDocumentFragment\u003c/code\u003e with a null parent, the traversal logic fails to detect the outer fallback raw-content container. Consequently, malicious input containing closing tags is rendered unescaped in the SSR output, leading to a container breakout and subsequent execution of injected markup when the page is parsed by a victim's browser. This bypasses Angular's built-in protections for standard text interpolation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the context of the user's session, potentially leading to session hijacking, data exfiltration, or unauthorized actions on behalf of the user. The vulnerability is reachable through both standard text interpolation and imperative DOM construction via \u003ccode\u003eRenderer2\u003c/code\u003e. Affected versions include \u003ccode\u003e@angular/platform-server\u003c/code\u003e v19.2.25 and below, 20.0.0 through 20.3.29, 21.0.0 through 21.2.21, and 22.0.0 through 22.1.3. Organizations utilizing Angular SSR with dynamic, user-controllable input rendered within the specified template containers are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized remediation involves updating the \u003ccode\u003e@angular/platform-server\u003c/code\u003e package to the latest patched releases. If immediate patching is not feasible, restrict the use of untrusted user input within \u003ccode\u003e\u0026lt;template\u0026gt;\u003c/code\u003e elements nested in \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;noembed\u0026gt;\u003c/code\u003e, or \u003ccode\u003e\u0026lt;noframes\u0026gt;\u003c/code\u003e. Security teams should audit codebases for components that use \u003ccode\u003eRenderer2\u003c/code\u003e to dynamically construct DOM structures involving these fallback elements to ensure input is sanitized before rendering.\u003c/p\u003e\n","date_modified":"2026-09-11T00:55:15Z","date_published":"2026-09-11T00:55:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/","summary":"An XSS vulnerability in Angular's server-side rendering serializer fails to escape closing tags within \u003ctemplate\u003e content nested inside fallback raw-content elements, allowing arbitrary script execution.","title":"Cross-Site Scripting in Angular Platform Server SSR","url":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:google:angular:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}