{"id":"CVE-2026-69149","aliases":["GHSA-vpx6-8pjr-4g3v"],"title":"Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)","summary":"Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)","severity":"high","cwe":["CWE-79"],"vendor":"angular","product":"@angular/platform-server","ecosystem":"npm","affected":["@angular/platform-server >= 22.0.0-next.0, < 22.0.7","@angular/platform-server >= 21.0.0-next.0, < 21.2.19","@angular/platform-server >= 20.0.0-next.0, < 20.3.27","@angular/platform-server <= 19.2.25"],"patched":["@angular/platform-server 22.0.7","@angular/platform-server 21.2.19","@angular/platform-server 20.3.27"],"published":"2026-08-03","updated":"2026-08-03","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vpx6-8pjr-4g3v","references":[{"url":"https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v"},{"url":"https://github.com/angular/angular/pull/69675"},{"url":"https://github.com/angular/angular/pull/69714"},{"url":"https://github.com/angular/angular/pull/69929"},{"url":"https://github.com/angular/angular/pull/69930"},{"url":"https://github.com/angular/domino/pull/32"},{"url":"https://github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56"},{"url":"https://github.com/advisories/GHSA-vpx6-8pjr-4g3v"}],"tags":["ghsa","npm"],"ingestedAt":"2026-08-03T16:26:24.172Z","epss":0.00206,"epssPercentile":0.10973,"slug":"CVE-2026-69149","body":"## Overview\n\nA Cross-Site Scripting (XSS) vulnerability exists in `@angular/platform-server`'s DOM emulation dependency (`domino`) when serializing the content of fallback raw-content elements (`<iframe>`, `<noembed>`, `<noframes>`, and `<noscript>`).\n\nWhen rendering dynamic text content inside fallback raw-content elements via template bindings, the template engine expects the browser to render the content safely. Under Server-Side Rendering (SSR), `domino` is configured with scripting enabled, meaning these elements are treated as raw-text elements.\n\nHowever, `domino`'s serializer previously did not escape text nodes within fallback raw-content elements (`<iframe>`, `<noembed>`, `<noframes>`, `<noscript>`) during DOM serialization. As a result, any occurrence of closing tags in the bound dynamic text was not escaped.\n\nThe unescaped closing tag could be serialized directly into the output HTML. When parsed by a browser or re-parsed during SSR post-processing without preserving raw-content parser state, an injected closing tag closes the element early, allowing an injected script block to execute in the user's browser context, causing same-origin Cross-Site Scripting (XSS).\n\n### Impact\n\nThis vulnerability allows an attacker to perform same-origin Cross-Site Scripting (XSS) attacks against any user visiting an SSR-rendered page that binds user-controlled data inside fallback raw-content elements (`<iframe>`, `<noembed>`, `<noframes>`, `<noscript>`). This can lead to session hijacking, credentials theft, unauthorized actions on behalf of users, and defacement.\n\n### Patched Versions\n\n- 22.0.7\n- 21.2.19\n- 20.3.27\n\n### Workarounds\nIf you cannot immediately update your dependencies, you can mitigate this issue using any of the following approaches:\n- **Disable critical CSS inlining**: Critical CSS inlining in Angular SSR post-processes the rendered HTML using `domino`. Disabling this step prevents `domino` from re-parsing and re-serializing the HTML during server-side rendering.\n  - In `angular.json`, set `inlineCritical` to `false` under style optimization options:\n    ```json\n    {\n      \"projects\": {\n        \"my-app\": {\n          \"architect\": {\n            \"build\": {\n              \"builder\": \"@angular/build:application\",\n              \"options\": {\n                \"optimization\": {\n                  \"styles\": {\n                    \"inlineCritical\": false\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    }\n    ```\n  - When rendering programmatically with `CommonEngine`, set `inlineCriticalCss: false` in your render options.\n- **Avoid binding user-controlled values** inside fallback raw-content elements (`<iframe>`, `<noembed>`, `<noframes>`, `<noscript>`).\n- **Sanitize user input** placed inside these elements to explicitly strip or escape closing tags before passing it to the template.\n\n## Affected packages\n\n- `@angular/platform-server >= 22.0.0-next.0, < 22.0.7`\n- `@angular/platform-server >= 21.0.0-next.0, < 21.2.19`\n- `@angular/platform-server >= 20.0.0-next.0, < 20.3.27`\n- `@angular/platform-server <= 19.2.25`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@angular/platform-server 22.0.7`\n- `@angular/platform-server 21.2.19`\n- `@angular/platform-server 20.3.27`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}