{"id":"CVE-2026-50555","aliases":["GHSA-hqr9-c56f-3x7f"],"url":"https://o3.security/vulnerability/CVE-2026-50555","summary":"Angular: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in @angular/platform-server","details":"A Cross-Site Scripting (XSS) vulnerability exists in `@angular/platform-server`'s DOM emulation dependency (`domino`) when serializing the content of raw-text elements (such as `<script>`, `<style>`, and `<iframe>`).\n\n`domino` supports escaping raw-text elements during serialization to prevent closing-tag breakout. However, a **Unicode index alignment bug** existed in this escaping logic.\n\nIn JavaScript, string lengths and character indices are calculated based on UTF-16 code units (where astral characters—such as emojis—occupy 2 code units / 4 bytes). If the bound dynamic text contained astral Unicode characters _before_ the closing tag (e.g. `</script>`, `</style>`, or `</iframe>`), the index offset calculation in `domino`'s replacement logic shifted.\n\nThis misalignment caused `domino` to fail to replace or escape the closing tag, leaving it raw and unescaped in the output HTML.\n\nAn attacker who controls the dynamic text can supply a payload containing both an astral Unicode character and a closing tag (e.g., `😀</iframe><script>alert(1)</script>`). When serialized on the server during SSR, the browser parses the unescaped closing tag, exits the raw-text context early, and executes the subsequent `<script>` block, leading to same-origin Cross-Site Scripting (XSS).\n\n### Impact\n\nThis vulnerability allows an attacker to perform same-origin Cross-Site Scripting (XSS) attacks against any user visiting an SSR-rendered page that binds user-controlled data inside raw-text elements. This can lead to session hijacking, credentials theft, unauthorized actions on behalf of users, and defacement.\n\n### Patched Versions\n\n- 22.0.0-rc.2\n- 21.2.16\n- 20.3.24\n- 19.2.25\n\n### Workarounds\n\nIf you cannot immediately update your dependencies, you can:\n\n- Avoid binding user-controlled values inside `<iframe>` or other raw-text elements.\n- Sanitize any user input placed inside raw-text elements to explicitly strip closing tags before passing it to the template.","published":"2026-06-22T15:37:29.943Z","modified":"2026-08-12T03:51:32.444931511Z","cvss":null,"epss":{"score":0.00267,"percentile":0.18961,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@angular/platform-server","fixedVersion":"22.0.0-rc.2"},{"ecosystem":"npm","name":"@angular/platform-server","fixedVersion":"21.2.16"},{"ecosystem":"npm","name":"@angular/platform-server","fixedVersion":"20.3.24"},{"ecosystem":"npm","name":"@angular/platform-server","fixedVersion":"19.2.25"},{"ecosystem":"npm","name":"@angular/platform-server","fixedVersion":null}],"fix":{"url":"https://github.com/angular/domino/pull/29","label":"angular/domino#29"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50555.json"},{"type":"ADVISORY","url":"https://github.com/angular/angular/security/advisories/GHSA-hqr9-c56f-3x7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50555"},{"type":"FIX","url":"https://github.com/angular/domino/pull/29"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.444931511Z"}}