Threat Advisory

Angular SSR Allows Unauthorized Access to Prerendered Static Pages

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity Path Traversal vulnerability affecting @angular/ssr versions >= 21.0.0, < 21.2.23 affecting @angular/ssr versions >= 20.0.0, < 20.3.36 exists in the prerendered page retrieval logic of CommonEngine, allowing unauthorized access to prerendered static pages from adjacent applications or build outputs. When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes CommonEngine to serve prerendered pages from sibling output directories. This occurs due to how relative URLs and Windows file paths are resolved and validated in CommonEngine, resulting in information disclosure of internal application data. The vulnerability allows unauthorized access to prerendered HTML pages located in sibling directories sharing the same name prefix as the public directory, such as an internal administration app adjacent to a main app. Only HTML files matching the Angular SSG marker regex are served, limiting the scope of the attack. This issue affects versions >= 22.0.0, < 22.1.7, and earlier versions of @angular/ssr, with patches available for versions 22.1.7, 21.2.23, and 20.3.36.

RECOMMENDATION:

We recommend you to update @angular/ssr to version 22.1.7, 21.2.23, or 20.3.36.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity Path Traversal vulnerability affecting @angular/ssr versions >= 21.0.0, < 21.2.23 affecting @angular/ssr versions >= 20.0.0, < 20.3.36 exists in the prerendered page retrieval logic of CommonEngine, allowing unauthorized access to prerendered static pages from adjacent applications or build outputs. When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes CommonEngine to serve prerendered pages from sibling output directories. This occurs due to how relative URLs and Windows file paths are resolved and validated in CommonEngine, resulting in information disclosure of internal application data. The vulnerability allows unauthorized access to prerendered HTML pages located in sibling directories sharing the same name prefix as the public directory, such as an internal administration app adjacent to a main app. Only HTML files matching the Angular SSG marker regex are served, limiting the scope of the attack. This issue affects versions >= 22.0.0, < 22.1.7, and earlier versions of @angular/ssr, with patches available for versions 22.1.7, 21.2.23, and 20.3.36.

RECOMMENDATION:

We recommend you to update @angular/ssr to version 22.1.7, 21.2.23, or 20.3.36.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu