Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-v3p8-whq6-r5jg
Summary
An XSS vulnerability exists in @angular/platform-server during server-side rendering (SSR) HTML serialization when traversing ancestor tags across <template> element boundaries. When an application renders untrusted user input within raw-text tags (<xmp>, <style>, <script>), comments, or text nodes inside a <template> that is nested within a fallback raw-content element (<noscript>, <iframe>, <noembed>, <noframes>), matching closing tags (e.g., </noscript>) are not escaped during HTML serialization. When rendered in a browser, this unescaped closing tag prematurely terminates the fallback container and executes trailing markup as active DOM elements.
Technical Description
In HTML5 parsing, fallback raw-content elements (<noscript>, <iframe>, <noembed>, <noframes>) place the browser's tokenizer into RAWTEXT mode. In this mode, inner content is parsed as literal text until an end tag matching the container tag name (e.g., </noscript>) is encountered.
To prevent XSS breakout vectors during SSR serialization, the DOM serializer inspects a node's ancestors to escape any matching fallback closing tags (</tag -> </tag). However:
- Per DOM specifications, the children of a
<template>element reside in a separateDocumentFragment(template.content), whose ownparentNodeisnull. - The serializer's ancestor traversal previously only inspected element nodes. When traversing upward from a node inside
template.content, traversal terminated immediately at theDocumentFragmentboundary. - Because traversal stopped before reaching the outer document tree, enclosing fallback raw-content ancestors (such as
<noscript>or<iframe>) were not discovered. As a result, closing sequences like</noscript>within<template>content were emitted unescaped.
Impact & Reachability
- Framework Guarantee Bypass: Angular guarantees that standard text interpolation (
{{ userInput }}bound as element text content) is safe by default without manual sanitization. This vulnerability bypasses that guarantee during SSR HTML serialization when untrusted input is interpolated inside template content within fallback containers. - Template Authoring: Writing literal
<xmp>or<style>directly inside a component's<template>markup requires relaxed template schema checks (CUSTOM_ELEMENTS_SCHEMAorNO_ERRORS_SCHEMA). However, standard HTML comments and text nodes inside<template>within<noscript>are reachable without relaxed schemas. - Imperative DOM Construction: Components or directives that construct DOM structures imperatively via
Renderer2bypass template compiler schema checks entirely and are unconditionally affected.
Proof of Concept (Minimal Reproduction)
import { Component } from '@angular/core';
@Component({
selector: 'app-root',
standalone: true,
template: `
<noscript>
<template>
<xmp>{{ payload }}</xmp>
</template>
</noscript>
`
})
export class AppComponent {
// Attacker-controlled input bound via standard text interpolation
payload = '</noscript><img src=x onerror=alert("SSR_TEMPLATE_XSS")>';
}
Vulnerable SSR Output:
<noscript><template><xmp></noscript><img src=x onerror=alert("SSR_TEMPLATE_XSS")></xmp></template></noscript>
Workarounds
- Avoid rendering untrusted user input inside
<template>elements nested within<noscript>,<iframe>,<noembed>, or<noframes>in server-rendered templates. - Avoid programmatic DOM assembly of
<template>elements inside fallback containers when handling untrusted data.
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights.
Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.
Probability that this vulnerability will be exploited in the wild within the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
- CVE-2026-88060Alias
- EUVD-2026-75703Alias
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard