@angular/platform-server is vulnerable to Cross-Site Scripting (XSS)
86
High Risk
@angular/platform-server contains a cross-site scripting (XSS) vulnerability in its server-side rendering (SSR) pipeline due to improper serialization of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). When user-controlled data is bound inside these elements, specially crafted input can inject closing tags and arbitrary HTML or JavaScript into the rendered output, leading to same-origin XSS in users' browsers.
You are affected if you are using a version that falls within the vulnerable range and you are using Angular Server-Side Rendering (SSR) and bind untrusted or user-controlled content inside fallback raw-content elements.
@angular/platform-server is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 20.3.26, 21.0.0 - 21.2.18 and 22.0.0 - 22.0.6.
Upgrade the @angular/platform-server library to the patch version. If this is not possible, disable critical CSS inlining (inlineCritical), avoid binding user-controlled data inside fallback raw-content elements.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant