Medium severity6.1NVD Advisory· Published Aug 3, 2026· Updated Aug 11, 2026
CVE-2026-69149
CVE-2026-69149
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (, , , and ). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@angular/platform-servernpm | >= 22.0.0-next.0, < 22.0.7 | 22.0.7 |
@angular/platform-servernpm | >= 21.0.0-next.0, < 21.2.19 | 21.2.19 |
@angular/platform-servernpm | >= 20.0.0-next.0, < 20.3.27 | 20.3.27 |
@angular/platform-servernpm | <= 19.2.25 | — |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56nvdPatchWEB
- github.com/advisories/GHSA-vpx6-8pjr-4g3vghsaADVISORY
- github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3vnvdVendor AdvisoryMitigationWEB
- github.com/angular/angular/pull/69675nvdIssue TrackingWEB
- github.com/angular/angular/pull/69714nvdIssue TrackingWEB
- github.com/angular/angular/pull/69929nvdIssue TrackingWEB
- github.com/angular/angular/pull/69930nvdIssue TrackingWEB
- github.com/angular/domino/pull/32nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.