Arbitrary Code Execution Vulnerability in Angular Expressions by Peerigon
CVE-2026-44643
9.3CRITICAL
What is CVE-2026-44643?
Angular Expressions, a standalone module for the Angular.JS web framework, contains a vulnerability in versions prior to 1.5.2. This issue allows attackers to craft malicious expressions utilizing filters that can escape the sandbox, leading to the execution of arbitrary code on the host system. Users are urged to upgrade to version 1.5.2 or later to mitigate this risk.
Affected Version(s)
angular-expressions < 1.5.2
