logo

Multiple Angular Language Service Extension Vulnerabilities Enable RCE Attacks

ID: 4e5802e2-7e8e-511c-b37c-23c8fbeec72d

STIX ID: report--4e5802e2-7e8e-511c-b37c-23c8fbeec72d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Abinaya

...
...

Security researchers discovered high-severity RCE vulnerabilities in the Angular Language Service VS Code extension (Angular.ng-template). One flaw allows JSDoc hover-rendered command links to execute commands due to unsanitized comments and an overly-trusted Markdown renderer; another lets a workspace-configured tsdk path cause the extension to require and run a malicious tsserverlibrary.js, enabling automatic code execution when a project is opened. Both bypass VS Code Workspace Trust, have low attack complexity and no privileges required, and are remediated in release 21.2.4—developers should update immediately and avoid opening untrusted repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.