Get real-time updates on Telegram
P5Verified
Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
CVE-2026-104871 affects @angular/ssr. EPSS 0.0042 (percentile 0.34023), scored 2026-10-04. Affected range: >= 22.0.0, < 22.1.7. Fixed version: 22.1.7. Affected range: >= 21.0.0, < 21.2.23. Fixed version: 21.2.23. Affected range: >= 20.0.0, < 20.3.36. Fixed version: 20.3.36. Affected range: <= 19.2.27.
- CVE
- CVE-2026-104871
- Product
- @angular/ssr
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.0042 · percentile 0.34023 · 2026-10-04
- KEV
- no
Affected products
- @angular/ssr · >= 22.0.0, < 22.1.7 · Fixed version: 22.1.7
- @angular/ssr · >= 21.0.0, < 21.2.23 · Fixed version: 21.2.23
- @angular/ssr · >= 20.0.0, < 20.3.36 · Fixed version: 20.3.36
- @angular/ssr · <= 19.2.27
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104871.html