Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-j3r3-mxqp-r2p4

HighCVSS 8.6 / 10
Published Sep 28, 2026·Last modified Sep 28, 2026
Affected Components(4)
npm logo@angular/platform-server
20.0.0 – 20.3.30
npm logo@angular/platform-server
< 19.2.26
npm logo@angular/platform-server
22.0.0 – 22.1.4
1 / 2
Description

Summary

An XSS vulnerability exists in @angular/platform-server during server-side rendering (SSR) HTML serialization of ProcessingInstruction DOM nodes (<?target data?>, nodeType === 7) when nested inside fallback raw-content elements (<noscript>, <iframe>, <noembed>, <noframes>). While processing instruction data escaped > to &gt;, it did not check for or escape matching closing tags of ancestor fallback elements (e.g., </noscript>). When rendered in a browser with scripting enabled, an unescaped closing tag sequence in a processing instruction prematurely closes the fallback raw-content tag and causes subsequent sibling elements to execute as live HTML.

Technical Description

In HTML5 parsing, fallback raw-content elements (<noscript>, <iframe>, <noembed>, <noframes>) place the browser's HTML tokenizer into RAWTEXT mode. In RAWTEXT mode, processing instruction tokens (<?...?>) are treated as literal raw text rather than bogus comments, and the parser ignores > or ?>. The only token sequence that terminates the container is an end tag matching the container tag name (</noscript, </iframe, etc.).

During server-side HTML serialization, processing instruction nodes previously only replaced > with &gt; (preventing bogus comment breakouts in normal HTML data states) but left < untouched. Crucially, processing instruction serialization never inspected ancestor fallback raw-content tags. As a result, if a ProcessingInstruction node inside <noscript> contained </noscript in its data payload, it was emitted unescaped as <?x </noscript ?>.

Impact & Reachability

  • Reachability: Processing instruction nodes cannot be authored directly through standard Angular template syntax (which parses <?...> into comment nodes in DOM position). Reaching this vulnerability requires application or library code calling inject(DOCUMENT).createProcessingInstruction(target, data) or Renderer2 DOM insertion methods with untrusted user input passed to data inside a fallback raw-content container.
  • Impact: In applications that programmatically construct processing instruction nodes inside fallback elements during server-side rendering, an attacker controlling the processing instruction data can break out of the container and execute arbitrary JavaScript in victims' browsers.

Proof of Concept (Minimal Reproduction)

import { Component, ElementRef, Renderer2, inject, DOCUMENT, AfterViewInit } from '@angular/core';

@Component({
  selector: 'app-root',
  standalone: true,
  template: `<noscript id="host"></noscript>`
})
export class AppComponent implements AfterViewInit {
  private r = inject(Renderer2);
  private el = inject(ElementRef);
  private doc = inject(DOCUMENT);

  ngAfterViewInit() {
    const host = this.el.nativeElement.querySelector('#host');
    
    // Attacker-controlled input passed as Processing Instruction data
    const pi = this.doc.createProcessingInstruction('x', '</noscript ');
    this.r.appendChild(host, pi);
    
    // Sibling markup that should remain inert inside <noscript>
    const img = this.r.createElement('img');
    this.r.setAttribute(img, 'src', 'x');
    this.r.setAttribute(img, 'onerror', 'alert("SSR_PI_XSS")');
    this.r.appendChild(host, img);
  }
}

Vulnerable SSR Output:

<noscript><?x </noscript ?><img src="x" onerror="alert('SSR_PI_XSS')"></noscript>

Workarounds

  • Avoid passing untrusted user input into document.createProcessingInstruction(target, data) when the node is inserted into <noscript>, <iframe>, <noembed>, or <noframes> during server-side rendering.
  • Manually sanitize or replace < with &lt; in any untrusted data passed to processing instruction nodes on the server.
Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
8.6

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights.

Threat Intelligence
6.2

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
N/A

Probability that this vulnerability will be exploited in the wild within the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Related Vulnerabilities
  • CVE-2026-88058
    Alias
  • EUVD-2026-75681
    Alias

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard