Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.
References
| Link | Resource |
|---|---|
| https://github.com/peerigon/angular-expressions/security/advisories/GHSA-pw8r-6689-xvf4 | Vendor Advisory |
Configurations
History
13 May 2026, 14:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Peerigon angular-expressions
Peerigon |
|
| References | () https://github.com/peerigon/angular-expressions/security/advisories/GHSA-pw8r-6689-xvf4 - Vendor Advisory | |
| CPE | cpe:2.3:a:peerigon:angular-expressions:*:*:*:*:*:node.js:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
11 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 16:17
Updated : 2026-05-13 14:54
NVD link : CVE-2026-44643
Mitre link : CVE-2026-44643
CVE.ORG link : CVE-2026-44643
JSON object : View
Products Affected
peerigon
- angular-expressions
CWE
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
