The GitHub Advisory Database said on 5 October that Angular's CommonEngine, a server-side rendering tool, has a path traversal flaw (a way to reach folders outside the intended one). It affects @angular/ssr/node, and @angular/ssr in earlier versions. On Windows, the advisory says, three steps combine. The address parser leaves backslashes untouched. Windows path joining treats a backslash as a folder divider, so the path leaves the public folder. The safety check compares only the start of the folder name, so dist\app-admin passes as dist\app.
Only HTML pages with Angular's prerender marker can be served, the advisory says. Secrets and config files cannot be read this way. The app must also run on Windows and have a sibling folder sharing the public folder's name prefix. The advisory says versions 19.2.27 and older are out of support and will not be patched. It links to releases 20.3.36, 21.2.23 and 22.1.7, but the text gives no affected ranges for supported lines. It does not say whether attacks have happened. Its workarounds are to clean request URLs, or to move to AngularNodeAppEngine.
A path check can look safe and still fail on one operating system. Leaders can ask three questions. Do we run Angular server rendering on Windows? Do internal apps sit beside public ones with similar names? What is our plan for versions that no longer get patches?