SCA: security update for @angular/platform-server (GHSA-j3r3-mxqp-r2p4)

high Tenable Cloud Security Plugin ID 448444

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Angular is a development platform for building mobile and desktop web applications using
TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side
rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes inside fallback
raw-content elements without escaping matching ancestor closing tags. ProcessingInstruction data escaped
greater-than characters but left less-than characters untouched and did not inspect fallback ancestors, so
data such as a matching closing tag prematurely terminates noscript, iframe, noembed, or noframes
containers. The vulnerable nodes cannot be authored through standard Angular templates; reachability
requires application or library code using inject(DOCUMENT).createProcessingInstruction with attacker-
controlled data or Renderer2 DOM insertion inside a fallback container. In HTML5 RAWTEXT parsing, the
premature close causes subsequent sibling elements to be interpreted as live HTML and enables arbitrary
JavaScript execution in a victim's browser. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
(CVE-2026-88058)

Solution

Update the @angular/platform-server library and its related packages to version 20.3.30 or later.

See Also

https://github.com/advisories/GHSA-j3r3-mxqp-r2p4

Plugin Details

Severity: High

ID: 448444

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.9

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-88058

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 6.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/10/2026

Reference Information

CVE: CVE-2026-88058