GHSA-pw8r-6689-xvf4
Angular Expressions - Remote Code Execution using filters
Quick fix
GHSA-pw8r-6689-xvf4 — angular-expressions: upgrade to the fixed version with the command below.
npm install angular-expressions@1.5.2Details
## Impact
An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.
Example of vulnerable code:
``` const expressions = require("angular-expressions"); const result = expressions.compile("a | __proto__")({}, {}); ```
This should throw the error : Filter '__proto__' is not defined, however, this shows :
Uncaught SyntaxError: Unexpected identifier 'Object'
With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.
## Vulnerable versions :
angular-expressions <= 1.5.1
## Patches
The problem has been patched in version 1.5.2 of angular-expressions.
## Credits
Credits go to San Gil from [www.securityoffice.io](https://securityoffice.io/) who has found the issue and reported it to us.
Are you affected?
Enter the version of the package you're using.