Description
The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Prerendered Pages
Action: Immediate Patch
AI Analysis

Impact

Path traversal weaknesses in Angular’s server‑side rendering tool enable an unauthenticated attacker to retrieve prerendered HTML files that reside in sibling directories on Windows systems. The flaw is triggered when a relative request URL includes a backslash parent‑traversal segment; the CommonEngine logic incorrectly accepts a sibling output directory whose name shares the configured public‑directory prefix. Although the vulnerability does not allow arbitrary file reads, it can expose content that contains the Angular SSG marker, thus compromising confidentiality of web application assets.

Affected Systems

The issue affects Angular CLI versions prior to 20.3.36, 21.2.23, and 22.1.7 – specifically the CommonEngine module within @angular/ssr/node and @angular/ssr (versions 17–18). It is relevant to Windows deployments that expose SSR endpoints and employ relative request URLs to CommonEngine.render. Other platforms or newer Angular releases are not impacted.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity; EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. In practice the attack requires that the target run Angular SSR on Windows, that a sibling output directory shares a name prefix with the public directory, and that a prerendered page containing the Angular SSG marker exists. Under these conditions an attacker can retrieve opaque content, but does not achieve arbitrary code execution or full system compromise. The exploit probability is therefore considered low to moderate under typical deployment scenarios.

Generated by OpenCVE AI on October 2, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Angular CLI to at least version 20.3.36, 21.2.23, or 22.1.7, or any newer release that contains the CommonEngine patch
  • Validate and sanitise all request URLs passed to CommonEngine.render, ensuring no backslash or parent‑traversal segments are accepted
  • Restrict public access to SSR endpoints by firewalling or moving them behind authentication or reverse‑proxy boundaries
  • As a temporary measure, rename or relocate sibling output directories so that they do not share a name prefix with the configured public directory

Generated by OpenCVE AI on October 2, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Angular
Angular angular Cli
Vendors & Products Angular
Angular angular Cli

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.
Title Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Angular Angular Cli
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T20:12:49.364Z

Reserved: 2026-10-02T14:59:11.775Z

Link: CVE-2026-104871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T20:17:00.910

Modified: 2026-10-02T20:17:00.910

Link: CVE-2026-104871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')