Cross-site scripting in Angular - CVE-2026-50556
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a user\'s browser context.
The vulnerability exists due to improper neutralization of input during web page generation in the domino serializer used by @angular/platform-server when serializing dynamic text content within tag and injected script to execute arbitrary script in a user\'s browser context.
User interaction is required to visit an SSR-rendered page that binds user-controlled data inside a