CVE-2026-104871 | Angular CLI up to 20.3.35/21.2.22/22.1.6 Prerendered Page Retrieval @angular/ssr/node CommonEngine.retrieveSSGPage path traversal
A vulnerability, which was classified as problematic, has been found in Angular CLI up to 20.3.35/21.2.22/22.1.6. The impacted element is the function CommonEngine.retrieveSSGPage of the file @angular/ssr/node of the component Prerendered Page Retrieval. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2026-104871. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More