Path Traversal Vulnerability in Angular SSR for Windows Deployments
CVE-2026-104871

6.3MEDIUM

Key Information:

Vendor

Angular

Vendor
CVE Published:
2 October 2026

What is CVE-2026-104871?

A vulnerability in the Angular server-side rendering (SSR) tool allows an unauthenticated requester to access sibling prerendered HTML pages on Windows systems. The problem arises from the retrieval logic in the CommonEngine where a relative request URL containing a backslash could lead to unintended access. This issue is confined to configurations that include another sibling output directory sharing the public directory prefix and contain Angular SSG markers. It does not facilitate arbitrary file retrieval. This vulnerability has been resolved in Angular SSR versions 20.3.36, 21.2.23, and 22.1.7. Users are encouraged to update to these versions to ensure their applications are secure.

Affected Version(s)

angular-cli < 20.3.36 < 20.3.36

angular-cli >= 21.0.0, < 21.2.23 < 21.0.0, 21.2.23

angular-cli >= 22.0.0, < 22.1.7 < 22.0.0, 22.1.7

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.