vulns.co
/
GKData.io MCP

Angular · 2 min read

Angular SSR: preserve output context through serialization and post-processing

Angular's advisory for CVE-2026-69149 describes unsafe serialization of untrusted text in fallback raw-content containers. A server-generated DOM can lose its intended inert meaning when later serialization and parsing interpret that text as structure. The maintainer confirms same-origin script-execution risk; session theft is a possible application-dependent consequence, not a documented production compromise.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Model every serialization and reparse boundary, including HTML post-processing. The linked remediation discussion shows that preserving comment semantics matters alongside escaping. The original advisory lists 22.0.7, 21.2.19 and 20.3.27 as fixes. Later advisories identify additional node and fragment cases, so these historical minimums do not establish comprehensive current remediation.

Before reading

  • Server-side rendering and browser output-context concepts
  • Basic trust-boundary and secure-input review

Context and limits

  • Exposure requires SSR and untrusted content in the affected rendering context. Ordinary Angular use alone does not establish exposure. Avoiding those bindings or the implicated post-processing path are scoped workarounds, not universal guarantees.
  • SkyZeroZx authored the linked remediation proposal on June 22, 2026; maintainer alan-agius4 merged it July 7. These are public-discussion and merge dates, not resource-edition or product-release dates.
  • The August 27 follow-ups describe separate processing-instruction and document-fragment reachability limits; they list 22.1.4, 21.2.22 and 20.3.30 as patched and older unsupported branches as unpatched. These follow-ups limit the original patch claim without asserting that every initial deployment reached every later case.
  • The processing-instruction advisory requires programmatic construction, unlike ordinary template syntax; the fragment advisory includes ordinary text-node cases. Both provide minimal demonstrations, but no production victim evidence.

Sources and provenance

  1. Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR Angular · reviewed 2026-10-03
  2. fix: escape fallback raw-content text nodes SkyZeroZx / Angular · reviewed 2026-10-03
  3. SSR XSS via Unescaped template Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements Angular · reviewed 2026-10-03
  4. SSR XSS via Unescaped Processing Instruction Nodes in Fallback Raw-Content Elements Angular · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software