Path Traversal Vulnerability in Angular SSR for Windows Deployments
CVE-2026-104871
What is CVE-2026-104871?
A vulnerability in the Angular server-side rendering (SSR) tool allows an unauthenticated requester to access sibling prerendered HTML pages on Windows systems. The problem arises from the retrieval logic in the CommonEngine where a relative request URL containing a backslash could lead to unintended access. This issue is confined to configurations that include another sibling output directory sharing the public directory prefix and contain Angular SSG markers. It does not facilitate arbitrary file retrieval. This vulnerability has been resolved in Angular SSR versions 20.3.36, 21.2.23, and 22.1.7. Users are encouraged to update to these versions to ensure their applications are secure.
Affected Version(s)
angular-cli < 20.3.36 < 20.3.36
angular-cli >= 21.0.0, < 21.2.23 < 21.0.0, 21.2.23
angular-cli >= 22.0.0, < 22.1.7 < 22.0.0, 22.1.7
