<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:13:09 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-309964</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-309964</link>
      <description>EUVD-2026-309964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-309964</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44643</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44643</link>
      <description>&lt;p&gt;Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44643</guid>
    </item>
    <item>
      <title>GHSA-pw8r-6689-xvf4 — Angular Expressions - Remote Code Execution using filters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pw8r-6689-xvf4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: angular-expressions&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.&lt;/p&gt;
&lt;p&gt;Example of vulnerable code:&lt;/p&gt;
&lt;p&gt;```
const expressions = require(&amp;#34;angular-expressions&amp;#34;);
const result = expressions.compile(&amp;#34;a | __proto__&amp;#34;)({}, {});
```&lt;/p&gt;
&lt;p&gt;This should throw the error : Filter &amp;#39;__proto__&amp;#39; is not defined, however, this shows :&lt;/p&gt;
&lt;p&gt;Uncaught SyntaxError: Unexpected identifier &amp;#39;Object&amp;#39;&lt;/p&gt;
&lt;p&gt;With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.&lt;/p&gt;
&lt;p&gt;## Vulnerable versions :&lt;/p&gt;
&lt;p&gt;angular-expressions &amp;lt;= 1.5.1&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in version 1.5.2 of angular-expressions.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Credits go to San Gil from [www.securityoffice.io](https://securityoffice.io/) who has found the issue and reported it to us.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: angular-expressions&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.&lt;/p&gt;
&lt;p&gt;Example of vulnerable code:&lt;/p&gt;
&lt;p&gt;```
const expressions = require(&amp;#34;angular-expressions&amp;#34;);
const result = expressions.compile(&amp;#34;a | __proto__&amp;#34;)({}, {});
```&lt;/p&gt;
&lt;p&gt;This should throw the error : Filter &amp;#39;__proto__&amp;#39; is not defined, however, this shows :&lt;/p&gt;
&lt;p&gt;Uncaught SyntaxError: Unexpected identifier &amp;#39;Object&amp;#39;&lt;/p&gt;
&lt;p&gt;With a more complex (undisclosed) payload, one can get full access to Arbitrary code execution on the system.&lt;/p&gt;
&lt;p&gt;## Vulnerable versions :&lt;/p&gt;
&lt;p&gt;angular-expressions &amp;lt;= 1.5.1&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;The problem has been patched in version 1.5.2 of angular-expressions.&lt;/p&gt;
&lt;p&gt;## Credits&lt;/p&gt;
&lt;p&gt;Credits go to San Gil from [www.securityoffice.io](https://securityoffice.io/) who has found the issue and reported it to us.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pw8r-6689-xvf4</guid>
    </item>
  </channel>
</rss>
