CVE-2026-88058: Cross-Site Scripting via Server-Side Serialization Discrepancy in @angular/platform-server
Vulnerability ID: CVE-2026-88058
CVSS Score: 8.6
Published: 2026-09-28
A high-severity Cross-Site Scripting (XSS) vulnerability in Angular server-side rendering (SSR) component allows unauthenticated attackers to execute arbitrary client-side JavaScript. The flaw is caused by a parsing discrepancy between the server-side DOM emulator, Domino, and standard client-side browser HTML5 parsers. When serializing ProcessingInstruction nodes inside raw-content fallback elements, Domino fails to escape matching ancestor closing tags, causing the client-side parser to transition out of raw-text mode prematurely and execute subsequent sibling elements as active HTML.
TL;DR
An unauthenticated attacker can achieve arbitrary JavaScript execution in a victim's browser by injecting closing tags into ProcessingInstruction nodes processed during server-side rendering, exploiting an escaping discrepancy in Angular's DOM emulator.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-79
- Attack Vector: Network
- CVSS Base Score: 8.6
- EPSS Score: 0.00875
- Impact: Arbitrary Client-Side Code Execution (XSS)
- Exploit Status: poc
- KEV Status: Not Listed
- Target Component: Domino HTML Serializer inside @angular/platform-server
Affected Systems
- @angular/platform-server
- domino
-
@angular/platform-server: >= 20.0.0, < 20.3.30 (Fixed in:
20.3.30) -
@angular/platform-server: >= 21.0.0, < 21.2.22 (Fixed in:
21.2.22) -
@angular/platform-server: >= 22.0.0, < 22.1.4 (Fixed in:
22.1.4) -
domino: < 2.1.7 (Fixed in:
2.1.7 (Commit 04f987dc08ff3736b427f50941adf1722458528f))
Code Analysis
Commit: 04f987d
Escape matching closing tag inside processing instruction
Commit: 73d8bbd
Bump domino dependency in Angular lockfile (v22/Main)
Commit: 89b2056
Bump domino dependency in Angular lockfile (v21/v20)
Exploit Details
- GitHub Issue #70146: Original bug report with comprehensive details explaining how nested templates bypass the serialization ancestor tree walk.
Mitigation Strategies
- Upgrade Angular framework dependencies to patched releases incorporating the upstream Domino fix.
- Sanitize all inputs processed by createProcessingInstruction or dynamic DOM node insertion functions on the server side.
- Implement a strong Content Security Policy (CSP) to mitigate client-side script execution impacts.
Remediation Steps:
- Identify all projects running Server-Side Rendering (SSR) with @angular/platform-server.
- Update package.json file to reference Angular version 20.3.30, 21.2.22, or 22.1.4 or higher.
- Regenerate package lock files (package-lock.json, pnpm-lock.yaml, or yarn.lock) to ensure the transitive 'domino' dependency resolves to a version containing commit 04f987dc08ff3736b427f50941adf1722458528f.
- Audit all uses of inject(DOCUMENT).createProcessingInstruction or Renderer2 DOM manipulation inside raw-content fallback elements like noscript or iframe.
- Redeploy the updated application and verify that serialized output properly escapes closing tag patterns.
References
- GitHub Security Advisory GHSA-j3r3-mxqp-r2p4
- Official CVE Record
- Angular Issue Tracking #70146
- NVD Vulnerability Details
- Domino Patch Commit
- Angular Integration Commit (v22/Main)
- Angular Integration Commit (v21/v20)
- Angular Release v22.1.4
- Angular Release v21.2.22
- Angular Release v20.3.30
Read the full report for CVE-2026-88058 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)