Intel

AIKIDO-2026-11061

@angular/platform-server is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-hqr9-c56f-3x7f Published Yesterday

86

High Risk

This Affects:

JS@angular/platform-server
0.0.0 - 19.2.24
Fixed in 19.2.25
20.0.0 - 20.3.23
Fixed in 20.3.24
21.0.0 - 21.2.15
Fixed in 21.2.16
Are you affected? Scan for Free

TL;DR

A Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of raw-text elements (such as script>, style>, and iframe>).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@angular/platform-server is vulnerable to Cross-Site Scripting (XSS) in versions 21.0.0 - 21.2.15, 20.0.0 - 20.3.23 and 0.0.0 - 19.2.24.

How to fix this

Upgrade the @angular/platform-server library to the patch version.