GHSA-v3p8-whq6-r5jg
HIGHCVE-2026-88060An XSS vulnerability exists in @angular/platform-server during server-side rendering (SSR) HTML serialization when traversing ancestor tags across <template> element boundaries. When an application renders untrusted user input within raw-text tags (<xmp>, <style>, <script>), comments, or text nodes inside a <template> that is nested within a fallback raw-content element (<noscript>, <iframe>, <noe
- Affected
- >= 22.0.0, < 22.1.4, >=22.0.0, <22.1.4
- Fixed in
- 22.1.4
- Weakness
- CWE-79
- Published
- 2026-09-10
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference