CVE-2026-104871 Angular SSR 路径遍历漏洞
影响未授权攻击者可读取同级预渲染 HTML 页面
Angular SSR 是 Angular 应用的服务端渲染工具。在 Windows 部署环境下,CommonEngine 的 retrieveSSGPage 预渲染页面检索逻辑会接受包含反斜杠父级遍历段的相对请求 URL,从而绕过路径前缀校验。该问题仅影响将相对请求 URL 传给 CommonEngine.render 且存在共享前缀的同级输出目录的 Windows 部署。
影响范围
@angular/ssr/node 及 @angular/ssr 受影响,涉及 20.3.36、21.2.23、22.1.7 之前的版本;@angular/ssr 的 17 至 18 版本亦受影响。
漏洞详情
漏洞类型为路径遍历。在 Windows 上,resolve:// URL 基址会保留反斜杠,path.join 将其解释为路径分隔符,而 pagePath.startsWith(normalize(publicPath)) 校验会错误接受名称共享配置公共目录前缀的同级输出目录。未认证请求者因此可读取包含 Angular SSG 标记的同级预渲染 HTML 页面,但不构成任意文件读取。
利用条件与风险
利用前提为 Windows 部署、向 CommonEngine.render 传入相对请求 URL、存在共享前缀的同级输出目录且包含符合条件的预渲染 Angular HTML。实战风险中等,仅限特定部署配置下的有限信息泄露。
修复建议
官方已在 20.3.36、21.2.23、22.1.7 版本中修复,建议升级至对应修复版本。临时缓解措施暂无公开信息。
The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash parent-traversal segment on Windows. The non-special resolve:// URL base preserves the backslash, path.join interprets it as a Windows separator, and the pagePath.startsWith(normalize(publicPath)) check incorrectly accepts a sibling output directory whose name shares the configured public-directory prefix. An unauthenticated requester can therefore retrieve a sibling prerendered HTML page when that page contains the Angular SSG marker. The issue is limited to Windows deployments that pass relative request URLs to CommonEngine.render, have a prefix-sharing sibling output directory, and contain qualifying prerendered Angular HTML; it does not provide arbitrary file read. This issue is fixed in versions 20.3.36, 21.2.23, and 22.1.7.