CVE-2026-44643
Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44643.json, https://github.com/peerigon/angular-expressions/security/advisories/GHSA-pw8r-6689-xvf4, https://nvd.nist.gov/vuln/detail/CVE-2026-44643