{"id":"GHSA-hqr9-c56f-3x7f","summary":"@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","details":"A Cross-Site Scripting (XSS) vulnerability exists in `@angular/platform-server`'s DOM emulation dependency (`domino`) when serializing the content of raw-text elements (such as `\u003cscript\u003e`, `\u003cstyle\u003e`, and `\u003ciframe\u003e`).\n\n`domino` supports escaping raw-text elements during serialization to prevent closing-tag breakout. However, a **Unicode index alignment bug** existed in this escaping logic.\n\nIn JavaScript, string lengths and character indices are calculated based on UTF-16 code units (where astral characters—such as emojis—occupy 2 code units / 4 bytes). If the bound dynamic text contained astral Unicode characters _before_ the closing tag (e.g. `\u003c/script\u003e`, `\u003c/style\u003e`, or `\u003c/iframe\u003e`), the index offset calculation in `domino`'s replacement logic shifted.\n\nThis misalignment caused `domino` to fail to replace or escape the closing tag, leaving it raw and unescaped in the output HTML.\n\nAn attacker who controls the dynamic text can supply a payload containing both an astral Unicode character and a closing tag (e.g., `😀\u003c/iframe\u003e\u003cscript\u003ealert(1)\u003c/script\u003e`). When serialized on the server during SSR, the browser parses the unescaped closing tag, exits the raw-text context early, and executes the subsequent `\u003cscript\u003e` block, leading to same-origin Cross-Site Scripting (XSS).\n\n### Impact\n\nThis vulnerability allows an attacker to perform same-origin Cross-Site Scripting (XSS) attacks against any user visiting an SSR-rendered page that binds user-controlled data inside raw-text elements. This can lead to session hijacking, credentials theft, unauthorized actions on behalf of users, and defacement.\n\n### Patched Versions\n\n- 22.0.0-rc.2\n- 21.2.16\n- 20.3.24\n- 19.2.25\n\n### Workarounds\n\nIf you cannot immediately update your dependencies, you can:\n\n- Avoid binding user-controlled values inside `\u003ciframe\u003e` or other raw-text elements.\n- Sanitize any user input placed inside raw-text elements to explicitly strip closing tags before passing it to the template.","aliases":["CVE-2026-50555"],"modified":"2026-07-15T22:15:55.306933623Z","published":"2026-06-15T17:20:30Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-15T17:20:30Z","nvd_published_at":"2026-06-22T18:16:43Z","cwe_ids":["CWE-79"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/angular/angular/security/advisories/GHSA-hqr9-c56f-3x7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50555"},{"type":"WEB","url":"https://github.com/angular/domino/pull/29"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"affected":[{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"22.0.0-next.0"},{"fixed":"22.0.0-rc.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hqr9-c56f-3x7f/GHSA-hqr9-c56f-3x7f.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0-next.0"},{"fixed":"21.2.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hqr9-c56f-3x7f/GHSA-hqr9-c56f-3x7f.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-next.0"},{"fixed":"20.3.24"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hqr9-c56f-3x7f/GHSA-hqr9-c56f-3x7f.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0-next.0"},{"fixed":"19.2.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hqr9-c56f-3x7f/GHSA-hqr9-c56f-3x7f.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"18.2.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-hqr9-c56f-3x7f/GHSA-hqr9-c56f-3x7f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}