VDB
Sign up
CRITICAL

GHSA-pw8r-6689-xvf4

Angular Expressions - Remote Code Execution using filters

Quick fix

GHSA-pw8r-6689-xvf4 — angular-expressions: upgrade to the fixed version with the command below.

npm install angular-expressions@1.5.2

Details

## Impact

An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.

Example of vulnerable code:

``` const expressions = require("angular-expressions"); const result = expressions.compile("a | __proto__")({}, {}); ```

This should throw the error : Filter '__proto__' is not defined, however, this shows :

Uncaught SyntaxError: Unexpected identifier 'Object'

With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.

## Vulnerable versions :

angular-expressions <= 1.5.1

## Patches

The problem has been patched in version 1.5.2 of angular-expressions.

## Credits

Credits go to San Gil from [www.securityoffice.io](https://securityoffice.io/) who has found the issue and reported it to us.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular-expressions
Introduced in: 0Fixed in: 1.5.2
Fixnpm install angular-expressions@1.5.2

References