<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Platform-Server (&gt;= 20.0.0, &lt; 20.3.30) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/platform-server--20.0.0--20.3.30/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 22:15:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/platform-server--20.0.0--20.3.30/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>XSS Vulnerability in Angular Server-Side Rendering via Processing Instructions</title><link>https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/</link><pubDate>Mon, 28 Sep 2026 22:15:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/</guid><description>Angular platform-server is vulnerable to XSS when ProcessingInstruction nodes containing untrusted input are nested within fallback raw-content elements during server-side rendering.</description><content:encoded><![CDATA[<p>Angular's <code>@angular/platform-server</code> package contains an XSS vulnerability (CVE-2026-88058) affecting server-side rendering (SSR) serialization of DOM <code>ProcessingInstruction</code> nodes. When these nodes are nested inside fallback raw-content elements like <code>&lt;noscript&gt;</code>, <code>&lt;iframe&gt;</code>, <code>&lt;noembed&gt;</code>, or <code>&lt;noframes&gt;</code>, the serializer fails to properly escape the closing tags of ancestor containers (e.g., <code>&lt;/noscript&gt;</code>) within the processing instruction data.</p>
<p>In browsers, fallback raw-content elements cause the parser to enter <code>RAWTEXT</code> mode, where the parser looks for specific closing tag sequences to terminate the block. Because the Angular SSR serializer only escaped <code>&gt;</code> and not <code>&lt;</code>, an attacker providing a payload containing <code>&lt;/noscript </code> within a <code>ProcessingInstruction</code> can cause the browser to prematurely close the container and treat sibling elements as active HTML. This allows for arbitrary JavaScript execution in the context of the user's session. The vulnerability affects multiple versions across Angular 19 through 22.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Application or library code programmatically calls <code>inject(DOCUMENT).createProcessingInstruction(target, data)</code> or uses <code>Renderer2</code> to insert nodes.</li>
<li>The application passes untrusted user input as the <code>data</code> parameter for the <code>ProcessingInstruction</code> node.</li>
<li>The node is inserted into a container that uses a fallback raw-content element (e.g., <code>&lt;noscript&gt;</code>).</li>
<li>The Angular server-side rendering engine serializes the DOM state to an HTML string.</li>
<li>The serializer fails to escape the <code>&lt;</code> character in the processing instruction data, emitting <code>&lt;?x &lt;/noscript ?&gt;</code>.</li>
<li>The generated HTML string is sent to the client browser.</li>
<li>The client browser parses the HTML in <code>RAWTEXT</code> mode; the <code>&lt;/noscript</code> sequence terminates the <code>&lt;noscript&gt;</code> block.</li>
<li>Sibling markup elements following the breakout sequence are parsed as live HTML, executing injected malicious JavaScript.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for reflected or stored XSS depending on how the application handles input and rendering, leading to potential session hijacking, unauthorized actions on behalf of the user, or theft of sensitive data within the application. The reachability depends on the application's programmatic use of the <code>ProcessingInstruction</code> API with untrusted data, which is uncommon but possible in custom Angular library or component logic.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to patched versions of <code>@angular/platform-server</code> (e.g., &gt;= 22.1.4, &gt;= 21.2.22, or &gt;= 20.3.30) if available for your specific branch, or migrate to a secure version.</li>
<li>Audit application code for usage of <code>document.createProcessingInstruction</code> or <code>Renderer2</code> DOM insertion methods, specifically looking for instances where user-supplied strings are passed to the <code>data</code> parameter.</li>
<li>Implement strict input validation or manual escaping of the <code>&lt;</code> character for any untrusted data destined for <code>ProcessingInstruction</code> nodes on the server until the software is patched.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>injection</category><category>web-application</category><category>server-side-rendering</category><category>angular</category></item></channel></rss>