angular-expressions is vulnerable to Eval Injection
95
Critical Risk
Affected versions of this package contain a sandbox escape vulnerability in angular-expressions. Specially crafted expressions can bypass sandbox restrictions and execute arbitrary code on the host system, leading to remote code execution.
You are affected if you are using a version which is within vulnerability ranges
angular-expressions is vulnerable to Eval Injection in versions 0.0.1 - 1.5.1.
Upgrade the angular-expressions library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant