DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-88058: CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server

Vulnerability ID: CVE-2026-88058
CVSS Score: 8.6
Published: 2026-09-28

A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.

TL;DR

An unauthenticated attacker can achieve arbitrary JavaScript execution in a victim's browser by injecting closing tags into ProcessingInstruction nodes processed during server-side rendering, exploiting an escaping discrepancy in Angular's DOM emulator.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-79
  • Attack Vector: Network
  • CVSS Base Score: 8.6
  • EPSS Score: 0.00875
  • Impact: Arbitrary Client-Side Code Execution (XSS)
  • Exploit Status: poc
  • KEV Status: Not Listed
  • Target Component: Domino HTML Serializer inside @angular/platform-server

Affected Systems

  • @angular/platform-server
  • domino
  • @angular/platform-server: >= 20.0.0, < 20.3.30 (Fixed in: 20.3.30)
  • @angular/platform-server: >= 21.0.0, < 21.2.22 (Fixed in: 21.2.22)
  • @angular/platform-server: >= 22.0.0, < 22.1.4 (Fixed in: 22.1.4)
  • domino: < 2.1.7 (Fixed in: 2.1.7 (Commit 04f987dc08ff3736b427f50941adf1722458528f))

Code Analysis

Commit: 04f987d

Escape matching closing tag inside processing instruction

Commit: 73d8bbd

Bump domino dependency in Angular lockfile (v22/Main)

Commit: 89b2056

Bump domino dependency in Angular lockfile (v21/v20)

Exploit Details

  • GitHub Issue #70146: Original bug report with comprehensive details explaining how nested templates bypass the serialization ancestor tree walk.

Mitigation Strategies

  • Upgrade Angular framework dependencies to patched releases incorporating the upstream Domino fix.
  • Sanitize all inputs processed by createProcessingInstruction or dynamic DOM node insertion functions on the server side.
  • Implement a strong Content Security Policy (CSP) to mitigate client-side script execution impacts.

Remediation Steps:

  1. Identify all projects running Server-Side Rendering (SSR) with @angular/platform-server.
  2. Update package.json file to reference Angular version 20.3.30, 21.2.22, or 22.1.4 or higher.
  3. Regenerate package lock files (package-lock.json, pnpm-lock.yaml, or yarn.lock) to ensure the transitive 'domino' dependency resolves to a version containing commit 04f987dc08ff3736b427f50941adf1722458528f.
  4. Audit all uses of inject(DOCUMENT).createProcessingInstruction or Renderer2 DOM manipulation inside raw-content fallback elements like noscript or iframe.
  5. Redeploy the updated application and verify that serialized output properly escapes closing tag patterns.

References


Read the full report for CVE-2026-88058 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)