\n````\n\nDuring client bootstrap, Angular recovers this state by looki","image":"https://o3.security/opengraph.png","datePublished":"2026-06-15T15:16:18Z","dateModified":"2026-07-15T22:30:45.836298104Z","url":"https://o3.security/vulnerability/CVE-2026-54267","inLanguage":"en","author":{"@id":"https://o3.security/#organization"},"publisher":{"@id":"https://o3.security/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://o3.security/vulnerability/CVE-2026-54267"},"speakable":{"@type":"SpeakableSpecification","cssSelector":["h1",".vuln-summary",".vuln-severity",".vuln-mitigation"]},"about":[{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"22.0.1"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"21.2.17"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"20.3.25"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm"}],"citation":[{"@type":"CreativeWork","name":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54267"},{"@type":"CreativeWork","name":"OSV.dev","url":"https://osv.dev/vulnerability/CVE-2026-54267"},{"@type":"CreativeWork","name":"FIRST.org EPSS","url":"https://www.first.org/epss/api-data?cve=CVE-2026-54267"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/security/advisories/GHSA-rgjc-h3x7-9mwg"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/pull/69064"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/commit/6bde84fa8e6a5770b54040fbbc9bf10d5d0386fa"}]}\n````\n\nDuring client bootstrap, Angular recovers this state by looki","url":"https://o3.security/vulnerability/CVE-2026-54267","identifier":"CVE-2026-54267","datePublished":"2026-06-15T15:16:18Z","dateModified":"2026-07-15T22:30:45.836298104Z","inLanguage":"en","license":"https://creativecommons.org/licenses/by/4.0/","keywords":["CVE-2026-54267","MEDIUM severity","CWE-79","CWE-471","CVE","vulnerability","security advisory"],"creator":{"@id":"https://o3.security/#organization"},"isAccessibleForFree":true,"citation":[{"@type":"CreativeWork","name":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54267"},{"@type":"CreativeWork","name":"OSV.dev","url":"https://osv.dev/vulnerability/CVE-2026-54267"},{"@type":"CreativeWork","name":"FIRST.org EPSS","url":"https://www.first.org/epss/api-data?cve=CVE-2026-54267"}],"variableMeasured":[{"@type":"PropertyValue","name":"CVSS Base Score","value":6.1,"description":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"@type":"PropertyValue","name":"Severity","value":"MEDIUM"},{"@type":"PropertyValue","name":"EPSS Percentile","value":8}]}\n````\n\nDuring client bootstrap, Angular recovers this state by looking up the element via `document.getElementById('ng-state')` and parsing its text content.\n\nBecause t"}},{"@type":"Question","name":"How severe is GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg has a CVSS score of 6.1/10, rated MEDIUM. Review your exposure and patch according to your risk tolerance."}},{"@type":"Question","name":"Which packages are affected by GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg affects the following packages: @angular/core (npm), @angular/core (npm), @angular/core (npm), @angular/core (npm). Ecosystems affected: npm."}},{"@type":"Question","name":"How do I fix GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"Update @angular/core to 22.0.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-rgjc-h3x7-9mwg is resolved across your whole dependency graph."}},{"@type":"Question","name":"How do I detect GHSA-rgjc-h3x7-9mwg in my npm dependencies?","acceptedAnswer":{"@type":"Answer","text":"Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @angular/core. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match."}},{"@type":"Question","name":"How do I mitigate GHSA-rgjc-h3x7-9mwg if there is no patch (or I can't update yet)?","acceptedAnswer":{"@type":"Answer","text":"If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands."}},{"@type":"Question","name":"How does O3 Security protect against GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"O3 pinpoints whether GHSA-rgjc-h3x7-9mwg is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed."}},{"@type":"Question","name":"Is GHSA-rgjc-h3x7-9mwg actively exploited in the wild?","acceptedAnswer":{"@type":"Answer","text":"No public exploit code has been indexed for GHSA-rgjc-h3x7-9mwg yet. This does not mean the vulnerability cannot be exploited — absence of public exploits does not imply safety. Apply the recommended fix and use O3 Security to monitor your exposure."}},{"@type":"Question","name":"What is the EPSS score for GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg has an EPSS (Exploit Prediction Scoring System) score of 0.2%, placing it in the 8th percentile of all CVEs. EPSS is maintained by FIRST.org and estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This score indicates relatively lower exploitation probability, though the CVSS severity should still guide your patching priority."}},{"@type":"Question","name":"What type of vulnerability is GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg is classified as Cross-site Scripting (XSS) (CWE-79), CWE-471 (CWE-471). These weakness types describe the underlying flaw category, which helps determine the potential impact and the right class of mitigation. This is a high-impact weakness class that often enables remote code execution or data exposure."}},{"@type":"Question","name":"When was GHSA-rgjc-h3x7-9mwg published, and has it been updated?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg was published on June 15, 2026 and was last updated on July 15, 2026. Advisory data evolves as severity scores, affected ranges, and exploit intelligence are revised — always check the latest version of the advisory before acting."}}]}
Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
MEDIUM severity

GHSA-rgjc-h3x7-9mwg

MEDIUMFix: angular/angular#69064

GHSA-rgjc-h3x7-9mwg is a medium-severity (CVSS 6.1) Cross-site Scripting (XSS) vulnerability in @angular/core. O3 Security confirms whether GHSA-rgjc-h3x7-9mwg is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Also known asCVE-2026-54267
Published
Jun 15, 2026
Updated
Jul 15, 2026
Affected
4 pkgs
Patched
3 / 4
Exploits
None indexed
Exploitation data as of Aug 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-rgjc-h3x7-9mwg.

EPSS Exploitation Probability

via FIRST.org ↗
0.2%probability of exploitation in next 30 days
Lower Risk+0.00%
Lower risk than most CVEs8th percentile — riskier than 8% of all scored CVEsHighest risk
0.00%0.23%0.45%0.68%0.2%0.2%Jul 26Aug 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

How urgent is this, really

GHSA-rgjc-h3x7-9mwg plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.

Where this sits among everything scored

Of 0 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.

Real-World Exposure

4 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

15Kother npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@angular/corenpm
6.0Mdownloads / week

Description

To optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydration(). During SSR, Angular serializes the application's runtime state (such as cached HttpClient responses) and outputs it into the HTML stream as a <script> tag with a predictable identifier:

<script type="application/json" id="ng-state">
    {"some-api-url": {"body": ...}}
</script>

During client bootstrap, Angular recovers this state by looking up the element via document.getElementById('ng-state') and parsing its text content.

Because the DOM element lookup for the state container is predictable and relies solely on the ID selector (ng-state), it is susceptible to DOM Clobbering.

If the application binds untrusted user input or CMS content to element properties such as id (e.g., <div [id]="userInput"> or <a id="ng-state">) before the genuine <script> tag is parsed by the browser, the attacker-controlled element takes precedence in the DOM lookup.

During hydration, when Angular calls document.getElementById('ng-state'), the browser returns the attacker's clobbered element. Angular then attempts to parse the text content or attributes of this clobbered element as JSON.

Impact

By clobbering the state element, the attacker can inject a custom JSON payload into Angular's TransferState cache. The most critical exploitation vector is poisoning the HTTP Transfer Cache.

  1. The attacker injects a clobbered ng-state element containing custom JSON.
  2. The JSON maps a key (representing a target API endpoint URL) to a malicious payload of the attacker's choice.
  3. During client-side initialization, Angular's HttpClient checks TransferState before making requests. Finding the poisoned key, HttpClient returns the forged response instantly instead of requesting the genuine backend API.

Depending on how the application processes and renders the affected API response, this can lead to:

  • DOM-based Cross-Site Scripting (XSS) if poisoned fields are rendered using unsafe bindings.
  • Privilege Escalation by spoofing user info or session details retrieved from poisoned API payloads.
  • UI Hijacking and redirection by spoofing configuration endpoints.

Patched Versions

  • 22.0.1
  • 21.2.17
  • 20.3.25

Workarounds

If you cannot immediately update to a patched Angular version, apply the following workarounds:

A. Avoid Dynamic/User-Controlled IDs

Avoid binding raw user-supplied values or dynamic CMS IDs directly to element attributes. If dynamic IDs are required, sanitize them or prepend a static safe prefix:

<!-- Vulnerable Pattern -->
<div [id]="userControlledInput">...</div>

<!-- Mitigated Pattern -->
<div [id]="'safe-prefix-' + userControlledInput">...</div>

B. Configure a Custom Application ID

Declaring a unique, non-predictable APP_ID changes the ID suffix of the state element, making it harder for attackers to predict and target:

// app.config.ts

import { APP_ID } from '@angular/core';
import { provideClientHydration } from '@angular/platform-browser';

export const appConfig = {
  providers: [
    { provide: APP_ID, useValue: 'unique-obfuscated-app-id' },
    provideClientHydration()
  ]
};

This changes the state element lookup ID from ng-state to unique-obfuscated-app-id-state.

Affected Packages

4 total 3 fixed
EcosystemPackageVulnerable rangeFix
📦npm@angular/core22.0.0-next.0&&< 22.0.122.0.1
📦npm@angular/core21.0.0-next.0&&< 21.2.1721.2.17
📦npm@angular/core20.0.0-next.0&&< 20.3.2520.3.25
📦npm@angular/coreall versionsNo fix

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @angular/core. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update @angular/core to 22.0.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-rgjc-h3x7-9mwg is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-rgjc-h3x7-9mwg is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-rgjc-h3x7-9mwg. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

To optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports **Hydration** via `provideClientHydration()`. During SSR, Angular serializes the application's runtime state (such as cached `HttpClient` responses) and outputs it into the HTML stream as a `<script>` tag with a predictable identifier: ```html <script type="application/json" id="ng-state"> {"some-api-url": {"body": ...}} </script> ```` During client bootstrap, Angular recovers this state by looking up the element via `document.getElementById('ng-state')` and parsing its text content. Because t
O3 Security · Impact-Aware SCA

Is GHSA-rgjc-h3x7-9mwg in your dependencies?

O3 detects GHSA-rgjc-h3x7-9mwg across npm dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.