{"id":"GHSA-7g7c-h8rr-7p6q","summary":"Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows","details":"A Path Traversal vulnerability exists in the prerendered (SSG) page retrieval logic of `CommonEngine` in `@angular/ssr/node` (and `@angular/ssr` in earlier versions). When deployed on Windows, an attacker can craft a request path with backslash directory traversal sequences that causes `CommonEngine` to serve prerendered pages from sibling output directories.\n\nThe vulnerability occurs due to how relative URLs and Windows file paths are resolved and validated:\n\n1. A request URL containing a backslash parent traversal segment (e.g., `/..\\app-admin`) is passed to `CommonEngine.render({ url })`.\n2. The engine parses the URL using `new URL(url, 'resolve://')`. Because `resolve://` is a non-special scheme under the WHATWG URL standard, backslashes are not normalized to forward slashes, leaving the `pathname` unnormalized as `/..\\app-admin`.\n3. The engine constructs the candidate file path using `join(publicPath, pathname, 'index.html')`. On Windows, `path.join` treats `\\` as a path delimiter, resolving the parent segment (`..\\`) out of `publicPath` (e.g., `dist\\app`) into a sibling directory (e.g., `dist\\app-admin\\index.html`).\n4. The containment check (`pagePath.startsWith(normalize(publicPath))`) performs a prefix match without a trailing path delimiter. Because the sibling folder name starts with the configured public folder name (e.g., `dist\\app-admin` starts with `dist\\app`), the check erroneously succeeds.\n5. If the target file exists and contains the Angular SSG marker (`ng-server-context=\"...ssg...\"`), `CommonEngine` reads and serves the sibling page instead of rendering the requested route.\n\n### Impact\n\nThis vulnerability allows unauthorized access to prerendered static pages from adjacent applications or build outputs:\n\n- **Information Disclosure:** Prerendered HTML pages located in sibling directories sharing the same name prefix as the public directory (e.g., an internal administration app `app-admin` adjacent to `app`) can be accessed by unauthorized users.\n- **Limited Scope:** Only HTML files matching the Angular SSG marker regex are served. Arbitrary non-Angular files, secrets, or configuration files without the SSG context attribute cannot be read through this mechanism.\n\n### Attack Preconditions\n\n- The application must use `CommonEngine` from `@angular/ssr/node` (or `@angular/ssr` in v17–v18).\n- The application must be hosted on Windows (where Node's `path.join` resolves `\\` as a path separator).\n- The application passes a relative request URL (such as `req.url` or `req.originalUrl` without origin) into `CommonEngine.render({ url })`.\n- A sibling directory exists whose name starts with the same prefix as the configured `publicPath` directory (e.g., `dist\\app-admin` alongside `dist\\app`).\n- The targeted sibling directory contains prerendered HTML output containing the Angular SSG marker.\n\n### Affected Versions\n\n- `\u003e= 22.0.0, \u003c 22.1.7`\n- `\u003e= 21.0.0, \u003c 21.2.23`\n- `\u003e= 20.0.0, \u003c 20.3.36`\n- `\u003c= 19.2.27`\n\n### Patches\n\n- `22.1.7`\n- `21.2.23`\n- `20.3.36`\n\n\u003e Versions `\u003c= 19.2.27` have reached End of Support / LTS expiration and will not be patched.\n\n### Workarounds\n\nUntil a patch is applied, developers using `CommonEngine` on Windows can sanitize request URLs in `server.ts` before passing them to `CommonEngine.render`, ensuring backslashes are replaced or that an absolute HTTP URL is constructed:\n\n```ts\nserver.use((req, res, next) =\u003e {\n  const { protocol, originalUrl, headers } = req;\n\n  // Normalize backslashes or construct a full HTTP URL (which forces WHATWG URL normalization)\n  const sanitizedUrl = `${protocol}://${headers.host}${originalUrl.replace(/\\\\/g, '/')}`;\n\n  commonEngine\n    .render({\n      bootstrap,\n      documentFilePath: indexHtml,\n      url: sanitizedUrl,\n      publicPath: distFolder,\n    })\n    .then((html) =\u003e res.send(html))\n    .catch((err) =\u003e next(err));\n});\n```\n\nAlternatively, migrate from the deprecated `CommonEngine` to `AngularNodeAppEngine`, which relies on manifest-based route matching rather than direct filesystem path resolution.","aliases":["CVE-2026-104871"],"modified":"2026-10-05T23:00:04.245230888Z","published":"2026-10-05T22:53:45Z","database_specific":{"github_reviewed_at":"2026-10-05T22:53:45Z","nvd_published_at":"2026-10-02T20:17:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/angular/angular-cli/security/advisories/GHSA-7g7c-h8rr-7p6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104871"},{"type":"WEB","url":"https://github.com/angular/angular-cli/commit/645e41a47d21b7651837a4250de99af0509626e2"},{"type":"WEB","url":"https://github.com/angular/angular-cli/commit/70748ca8e76fe4b42798719410336119d943e755"},{"type":"WEB","url":"https://github.com/angular/angular-cli/commit/bb72145f9ab45aee29f523236b3a25cd0813a841"},{"type":"WEB","url":"https://github.com/angular/angular-cli/commit/c3e5982e49705f0f6a913cb94622b4c555d2d914"},{"type":"PACKAGE","url":"https://github.com/angular/angular-cli"},{"type":"WEB","url":"https://github.com/angular/angular-cli/releases/tag/v20.3.36"},{"type":"WEB","url":"https://github.com/angular/angular-cli/releases/tag/v21.2.23"},{"type":"WEB","url":"https://github.com/angular/angular-cli/releases/tag/v22.1.7"}],"affected":[{"package":{"name":"@angular/ssr","ecosystem":"npm","purl":"pkg:npm/%40angular/ssr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"22.0.0"},{"fixed":"22.1.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7g7c-h8rr-7p6q/GHSA-7g7c-h8rr-7p6q.json"}},{"package":{"name":"@angular/ssr","ecosystem":"npm","purl":"pkg:npm/%40angular/ssr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0"},{"fixed":"21.2.23"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7g7c-h8rr-7p6q/GHSA-7g7c-h8rr-7p6q.json"}},{"package":{"name":"@angular/ssr","ecosystem":"npm","purl":"pkg:npm/%40angular/ssr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0"},{"fixed":"20.3.36"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7g7c-h8rr-7p6q/GHSA-7g7c-h8rr-7p6q.json"}},{"package":{"name":"@angular/ssr","ecosystem":"npm","purl":"pkg:npm/%40angular/ssr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"19.2.27"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-7g7c-h8rr-7p6q/GHSA-7g7c-h8rr-7p6q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}