Junglewise Threat Intelligence

CVE-2026-44643: Peerigon Angular Expressions sandbox escape via malicious filters

CVE-2026-44643 · Severity: critical · CVSS 10 · Published 2026-05-11

Technologies: Peerigon Angular-Expressions. Vendors: Peerigon.

Executive brief

Angular Expressions is a library used to evaluate code-like expressions in web applications. A security flaw allows an attacker to bypass the library's safety restrictions by using specially crafted filters. This can lead to unauthorized code execution on the server or system running the application, potentially resulting in a full system takeover or data breach.

Technical details

A sandbox escape vulnerability exists in the angular-expressions library (an npm package) prior to version 1.5.2. The vulnerability is classified as Eval Injection (CWE-95) and occurs when the library incorrectly neutralizes code syntax within filters. An attacker can provide a malicious expression that leverages these filters to break out of the intended sandbox environment. This allows for arbitrary code execution on the host system. The issue is reachable over the network without authentication if the application evaluates user-supplied input through the library's compile function. The vulnerability is fixed in version 1.5.2.

Affected products

  • peerigon angular-expressions < 1.5.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published by maintainer
  • 2026-05-11: disclosed: CVE published to NVD

References

Related threats