Intel

AIKIDO-2026-10786

angular-expressions is vulnerable to Eval Injection

Eval InjectionCVE-2026-44643 Published May 8, 2026

95

Critical Risk

This Affects:

JSangular-expressions
0.0.1 - 1.5.1
Fixed in 1.5.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a sandbox escape vulnerability in angular-expressions. Specially crafted expressions can bypass sandbox restrictions and execute arbitrary code on the host system, leading to remote code execution.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

angular-expressions is vulnerable to Eval Injection in versions 0.0.1 - 1.5.1.

How to fix this

Upgrade the angular-expressions library to the patch version.