Impact
Path traversal weaknesses in Angular’s server‑side rendering tool enable an unauthenticated attacker to retrieve prerendered HTML files that reside in sibling directories on Windows systems. The flaw is triggered when a relative request URL includes a backslash parent‑traversal segment; the CommonEngine logic incorrectly accepts a sibling output directory whose name shares the configured public‑directory prefix. Although the vulnerability does not allow arbitrary file reads, it can expose content that contains the Angular SSG marker, thus compromising confidentiality of web application assets.
Affected Systems
The issue affects Angular CLI versions prior to 20.3.36, 21.2.23, and 22.1.7 – specifically the CommonEngine module within @angular/ssr/node and @angular/ssr (versions 17–18). It is relevant to Windows deployments that expose SSR endpoints and employ relative request URLs to CommonEngine.render. Other platforms or newer Angular releases are not impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity; EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. In practice the attack requires that the target run Angular SSR on Windows, that a sibling output directory shares a name prefix with the public directory, and that a prerendered page containing the Angular SSG marker exists. Under these conditions an attacker can retrieve opaque content, but does not achieve arbitrary code execution or full system compromise. The exploit probability is therefore considered low to moderate under typical deployment scenarios.
OpenCVE Enrichment