CVE-2026-88058 | Angular up to 19.2.25/20.3.29/21.2.21/22.1.3 Server-Side Rendering createProcessingInstruction data cross site scripting

SecurityVulns

A vulnerability categorized as problematic has been discovered in Angular up to 19.2.25/20.3.29/21.2.21/22.1.3. The impacted element is the function createProcessingInstruction of the component Server-Side Rendering. Such manipulation of the argument data leads to cross site scripting.

This vulnerability is referenced as CVE-2026-88058. It is possible to launch the attack remotely. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More