CVE-2026-44643Disclosure(peerigon / angular-expressions)

LOWCVSS 10.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch peerigon angular-expressions systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular-expressions

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
angular-expressions

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-11: 3Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 305-11
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Angular Expressions Remote Code Execution (CVE-2026-44643) A critical vulnerability in the angular-expressions library allows unauthenticated attackers to escape the sandbox and execute arbitrary code on the host system. By crafting malicious expressions using filters (e.g., abusing __proto__), an attacker can trigger an eval injection to gain full Remote Code Execution (RCE). 👉 Affected: angular-expressions <= 1.5.1 | Upgrade to 1.5.2

    Post summary

    A critical RCE flaw in angular-expressions allowing unauthenticated attackers to escape the sandbox; mitigated by upgrading to version 1.5.2.

    00010102
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44643 Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using f… https://www.cve.org/CVERecord?id=CVE-2026-44643

    Post summary

    The statement highlights a CVE in AngularJS (pre-1.5.2) that permits attackers to create malicious expressions, with no PoC, exploit code, or mitigation details provided.

    0000073
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44643 Sandbox Escape via Malicious Expressions in Angular.JS Versions Below 1.5.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44643

    Post summary

    The text announces CVE-2026-44643, describing a sandbox escape vulnerability in Angular.JS versions below 1.5.2, and links to a detailed page, but provides no PoC, exploit code, or active exploitation claims.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppeerigonangular-expressions-node.js-

Explore more