<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:15:57.378477+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-11152</id>
    <title>bdu:2024-11152</title>
    <updated>2026-10-06T17:15:57.381740+00:00</updated>
    <content>bdu:2024-11152</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-11152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-206608</id>
    <title>EUVD-2026-206608</title>
    <updated>2026-10-06T17:15:57.381771+00:00</updated>
    <content>EUVD-2026-206608</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-206608"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-54152</id>
    <title>fkie_cve-2024-54152</title>
    <updated>2026-10-06T17:15:57.381786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to `__proto__` globally or make sure that one uses the function with just one argument.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-54152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5462-4vcx-jh7j</id>
    <title>GHSA-5462-4vcx-jh7j — Angular Expressions - Remote Code Execution when using locals</title>
    <updated>2026-10-06T17:15:57.381815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: angular-expressions</p>
<p>### Impact</p>
<p>An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.</p>
<p>Example of vulnerable code:</p>
<p>```js
const expressions = require("angular-expressions");
const result = expressions.compile("__proto__.constructor")({}, {});
// result should be undefined, however for versions &lt;=1.4.2, it returns an object.
```</p>
<p>With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.</p>
<p>### Patches</p>
<p>The problem has been patched in version 1.4.3 of angular-expressions.</p>
<p>### Workarounds</p>
<p>There is one workaround if it not possible for you to update :</p>
<p>* Make sure that you use the compiled function with just one argument : ie this is not vulnerable : 
    `const result = expressions.compile("__proto__.constructor")({});` : in this case you lose the feature of locals if you need it.</p>
<p>### Credits</p>
<p>Credits go to [JorianWoltjer](https://github.com/JorianWoltjer) who has found the issue and reported it to use. https://jorianwoltjer.com/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5462-4vcx-jh7j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-54152</id>
    <title>Withdrawn: UBUNTU-CVE-2024-54152</title>
    <updated>2026-10-06T17:15:57.381854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: angular.js, Ubuntu:18.04:LTS: angular.js, Ubuntu:20.04:LTS: angular.js, Ubuntu:22.04:LTS: angular.js, Ubuntu:24.04:LTS: angular.js, Ubuntu:25.10: angular.js, Ubuntu:25.04: angular.js</p>
<p>Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system. With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system. The problem has been patched in version 1.4.3 of Angular Expressions. Two possible workarounds are available. One may either disable access to `__proto__` globally or make sure that one uses the function with just one argument.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-54152"/>
  </entry>
</feed>
