CVE-2026-104871 | Angular CLI up to 20.3.35/21.2.22/22.1.6 Prerendered Page Retrieval @angular/ssr/node CommonEngine.retrieveSSGPage path traversal

SecurityVulns

A vulnerability, which was classified as problematic, has been found in Angular CLI up to 20.3.35/21.2.22/22.1.6. The impacted element is the function CommonEngine.retrieveSSGPage of the file @angular/ssr/node of the component Prerendered Page Retrieval. Performing a manipulation results in path traversal.

This vulnerability is identified as CVE-2026-104871. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More