Skip to content
Brief Security & Trust ·

Angular SSR flaw on Windows can expose pages from neighbouring folders

GitHub's advisory says CommonEngine can serve prerendered pages from the wrong directory when it runs on Windows.

In brief
  • Angular's CommonEngine on Windows can be tricked into serving prerendered pages from a sibling folder. Versions 19.2.27 and older will not be patched.
  • Only pages with Angular's prerender marker can be reached, and several conditions must all be true.

The GitHub Advisory Database said on 5 October that Angular's CommonEngine, a server-side rendering tool, has a path traversal flaw (a way to reach folders outside the intended one). It affects @angular/ssr/node, and @angular/ssr in earlier versions. On Windows, the advisory says, three steps combine. The address parser leaves backslashes untouched. Windows path joining treats a backslash as a folder divider, so the path leaves the public folder. The safety check compares only the start of the folder name, so dist\app-admin passes as dist\app.

Only HTML pages with Angular's prerender marker can be served, the advisory says. Secrets and config files cannot be read this way. The app must also run on Windows and have a sibling folder sharing the public folder's name prefix. The advisory says versions 19.2.27 and older are out of support and will not be patched. It links to releases 20.3.36, 21.2.23 and 22.1.7, but the text gives no affected ranges for supported lines. It does not say whether attacks have happened. Its workarounds are to clean request URLs, or to move to AngularNodeAppEngine.

A path check can look safe and still fail on one operating system. Leaders can ask three questions. Do we run Angular server rendering on Windows? Do internal apps sit beside public ones with similar names? What is our plan for versions that no longer get patches?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: GitHub Advisory Database.