GHSA-5462-4vcx-jh7j
Angular Expressions - Remote Code Execution when using locals
Quick fix
GHSA-5462-4vcx-jh7j — angular-expressions: upgrade to the fixed version with the command below.
npm install angular-expressions@1.4.3Details
### Impact
An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.
Example of vulnerable code:
```js const expressions = require("angular-expressions"); const result = expressions.compile("__proto__.constructor")({}, {}); // result should be undefined, however for versions <=1.4.2, it returns an object. ```
With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.
### Patches
The problem has been patched in version 1.4.3 of angular-expressions.
### Workarounds
There is one workaround if it not possible for you to update :
* Make sure that you use the compiled function with just one argument : ie this is not vulnerable : `const result = expressions.compile("__proto__.constructor")({});` : in this case you lose the feature of locals if you need it.
### Credits
Credits go to [JorianWoltjer](https://github.com/JorianWoltjer) who has found the issue and reported it to use. https://jorianwoltjer.com/
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/peerigon/angular-expressions/security/advisories/GHSA-5462-4vcx-jh7j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-54152[ADVISORY]
- https://github.com/peerigon/angular-expressions/commit/97f7ad94006156eeb97fc942332578b6cfbf8eef[WEB]
- https://github.com/peerigon/angular-expressions[PACKAGE]