SCA: security update for @angular/platform-server (GHSA-v3p8-whq6-r5jg)

high Tenable Self-Hosted Container Security Plugin ID 447942

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Angular is a development platform for building mobile and desktop web applications using
TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side
rendering (SSR) in @angular/platform-server serializes untrusted input inside template content nested in
fallback raw-content elements such as noscript, iframe, noembed, and noframes. The Domino serializer's
fallbackRawContentTags traversal stopped at the DocumentFragment used by template.content, so matching
closing tags in xmp, style, script, comments, or text nodes were not escaped. Standard interpolation with
comments or text nodes is reachable without relaxed schemas; literal xmp or style requires
CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, while Renderer2 imperative DOM construction is unconditionally
affected. When HTML5 RAWTEXT browser parsing encounters the unescaped closing tag, it exits the fallback
container and interprets trailing markup as active DOM elements, enabling arbitrary JavaScript execution.
This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4. (CVE-2026-88060)

Solution

Update the @angular/platform-server library and its related packages to version 20.3.30 or later.

See Also

https://github.com/advisories/GHSA-v3p8-whq6-r5jg

Plugin Details

Severity: High

ID: 447942

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/11/2026

Updated: 9/11/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-88060

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 6.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/10/2026

Vulnerability Publication Date: 9/10/2026

Reference Information

CVE: CVE-2026-88060