{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/platform-server--22.0.0--22.1.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:angular:platform_server:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-88058"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["platform-server (\u003e= 22.0.0, \u003c 22.1.4)","platform-server (\u003e= 21.0.0, \u003c 21.2.22)","platform-server (\u003e= 20.0.0, \u003c 20.3.30)","platform-server (\u003c= 19.2.25)"],"_cs_severities":["high"],"_cs_tags":["xss","injection","web-application","server-side-rendering","angular"],"_cs_type":"advisory","_cs_vendors":["Angular"],"content_html":"\u003cp\u003eAngular's \u003ccode\u003e@angular/platform-server\u003c/code\u003e package contains an XSS vulnerability (CVE-2026-88058) affecting server-side rendering (SSR) serialization of DOM \u003ccode\u003eProcessingInstruction\u003c/code\u003e nodes. When these nodes are nested inside fallback raw-content elements like \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;noembed\u0026gt;\u003c/code\u003e, or \u003ccode\u003e\u0026lt;noframes\u0026gt;\u003c/code\u003e, the serializer fails to properly escape the closing tags of ancestor containers (e.g., \u003ccode\u003e\u0026lt;/noscript\u0026gt;\u003c/code\u003e) within the processing instruction data.\u003c/p\u003e\n\u003cp\u003eIn browsers, fallback raw-content elements cause the parser to enter \u003ccode\u003eRAWTEXT\u003c/code\u003e mode, where the parser looks for specific closing tag sequences to terminate the block. Because the Angular SSR serializer only escaped \u003ccode\u003e\u0026gt;\u003c/code\u003e and not \u003ccode\u003e\u0026lt;\u003c/code\u003e, an attacker providing a payload containing \u003ccode\u003e\u0026lt;/noscript \u003c/code\u003e within a \u003ccode\u003eProcessingInstruction\u003c/code\u003e can cause the browser to prematurely close the container and treat sibling elements as active HTML. This allows for arbitrary JavaScript execution in the context of the user's session. The vulnerability affects multiple versions across Angular 19 through 22.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eApplication or library code programmatically calls \u003ccode\u003einject(DOCUMENT).createProcessingInstruction(target, data)\u003c/code\u003e or uses \u003ccode\u003eRenderer2\u003c/code\u003e to insert nodes.\u003c/li\u003e\n\u003cli\u003eThe application passes untrusted user input as the \u003ccode\u003edata\u003c/code\u003e parameter for the \u003ccode\u003eProcessingInstruction\u003c/code\u003e node.\u003c/li\u003e\n\u003cli\u003eThe node is inserted into a container that uses a fallback raw-content element (e.g., \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe Angular server-side rendering engine serializes the DOM state to an HTML string.\u003c/li\u003e\n\u003cli\u003eThe serializer fails to escape the \u003ccode\u003e\u0026lt;\u003c/code\u003e character in the processing instruction data, emitting \u003ccode\u003e\u0026lt;?x \u0026lt;/noscript ?\u0026gt;\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe generated HTML string is sent to the client browser.\u003c/li\u003e\n\u003cli\u003eThe client browser parses the HTML in \u003ccode\u003eRAWTEXT\u003c/code\u003e mode; the \u003ccode\u003e\u0026lt;/noscript\u003c/code\u003e sequence terminates the \u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e block.\u003c/li\u003e\n\u003cli\u003eSibling markup elements following the breakout sequence are parsed as live HTML, executing injected malicious JavaScript.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for reflected or stored XSS depending on how the application handles input and rendering, leading to potential session hijacking, unauthorized actions on behalf of the user, or theft of sensitive data within the application. The reachability depends on the application's programmatic use of the \u003ccode\u003eProcessingInstruction\u003c/code\u003e API with untrusted data, which is uncommon but possible in custom Angular library or component logic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to patched versions of \u003ccode\u003e@angular/platform-server\u003c/code\u003e (e.g., \u0026gt;= 22.1.4, \u0026gt;= 21.2.22, or \u0026gt;= 20.3.30) if available for your specific branch, or migrate to a secure version.\u003c/li\u003e\n\u003cli\u003eAudit application code for usage of \u003ccode\u003edocument.createProcessingInstruction\u003c/code\u003e or \u003ccode\u003eRenderer2\u003c/code\u003e DOM insertion methods, specifically looking for instances where user-supplied strings are passed to the \u003ccode\u003edata\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or manual escaping of the \u003ccode\u003e\u0026lt;\u003c/code\u003e character for any untrusted data destined for \u003ccode\u003eProcessingInstruction\u003c/code\u003e nodes on the server until the software is patched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T22:15:27Z","date_published":"2026-09-28T22:15:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/","summary":"Angular platform-server is vulnerable to XSS when ProcessingInstruction nodes containing untrusted input are nested within fallback raw-content elements during server-side rendering.","title":"XSS Vulnerability in Angular Server-Side Rendering via Processing Instructions","url":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Platform-Server (\u003e= 22.0.0, \u003c 22.1.4)","version":"https://jsonfeed.org/version/1.1"}