CVE-2026-69149Disclosure(angular / angular)

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch angular angular systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
angular

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-03: 2Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-03: 208-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Multiple High-Severity Vulnerabilities Fixed in Angular Ecosystem Angular released patches addressing three high-severity flaws across its compiler, core, and SSR packages: 1️⃣ CVE-2026-68945 (8.8): SSR HttpTransferCache key collision leading to response reuse & cache poisoning | Affected: @angular/common 2️⃣ CVE-2026-69149 (8.6): SSR XSS via unescaped text nodes in DOM emulation (domino) | Affected: @angular/platform-server 3️⃣ CVE-2026-69151 (7.6): i18n pipeline XSS allowing translation files to inject JS via i18n-on* | Affected: @angular/compiler, @angular/core 👉 Impact: Cross-request state poisoning and arbitrary script execution | Upgrade to Angular 20.3.27, 21.2.19, or 22.0.2

    Post summary

    Angular released patches for three high‑severity CVEs, detailing affected packages and recommending specific upgrade versions.

    00000103
    280 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-69149 Cross-Site Scripting Vulnerability in Angular Platform-Server DOM Emulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-69149

    Post summary

    The brief notice announces CVE‑2026‑69149 as an XSS flaw in Angular Platform‑Server DOM emulation, providing only high‑level details with no mention of PoC, exploitation, or patch information.

    0000088
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular-node.js-

Explore more