CVE-2026-104871: Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of CommonEngine in @angular/ssr/node (and @angular/ssr in earlier versions). When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes CommonEngine to serve prerendered pages from sibling output directories.
The vulnerability occurs due to how relative URLs and Windows file paths are resolved and validated:
- A request URL containing a backslash parent traversal segment (e.g.,
/..\app-admin) is passed toCommonEngine.render({ url }). - The engine parses the URL using
new URL(url, 'resolve://'). Becauseresolve://is a non-special scheme under the WHATWG URL standard, backslashes are not normalized to forward slashes, leaving thepathnameunnormalized as/..\app-admin. - The engine constructs the candidate file path using
join(publicPath, pathname, 'index.html'). On Windows,path.jointreats\as a path delimiter, resolving the parent segment (..\) out ofpublicPath(e.g.,dist\app) into a sibling directory (e.g.,dist\app-admin\index.html). - The containment check (
pagePath.startsWith(normalize(publicPath))) performs a prefix match without a trailing path delimiter. Because the sibling folder name starts with the configured public folder name (e.g.,dist\app-adminstarts withdist\app), the check erroneously succeeds. - If the target file exists and contains the Angular SSG marker (
ng-server-context="...ssg..."),CommonEnginereads and serves the sibling page instead of rendering the requested route.
References
- github.com/advisories/GHSA-7g7c-h8rr-7p6q
- github.com/angular/angular-cli/commit/645e41a47d21b7651837a4250de99af0509626e2
- github.com/angular/angular-cli/commit/70748ca8e76fe4b42798719410336119d943e755
- github.com/angular/angular-cli/commit/bb72145f9ab45aee29f523236b3a25cd0813a841
- github.com/angular/angular-cli/commit/c3e5982e49705f0f6a913cb94622b4c555d2d914
- github.com/angular/angular-cli/releases/tag/v20.3.36
- github.com/angular/angular-cli/releases/tag/v21.2.23
- github.com/angular/angular-cli/releases/tag/v22.1.7
- github.com/angular/angular-cli/security/advisories/GHSA-7g7c-h8rr-7p6q
- nvd.nist.gov/vuln/detail/CVE-2026-104871
Code Behaviors & Features
Detect and mitigate CVE-2026-104871 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →