logo

Angular Expressions Vulnerability Let Attackers Gain Full System Access

ID: e45b45b6-1fda-59ab-8531-c43bbb29f4c9

STIX ID: report--e45b45b6-1fda-59ab-8531-c43bbb29f4c9

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-01-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical remote code execution vulnerability (CVE-2024-54152, CVSS 9.3) was discovered in the Angular Expressions module allowing attackers to break the sandbox via the "proto" property and execute arbitrary commands; a public PoC demonstrates the impact and the maintainer released version 1.4.3 to address the issue while recommending mitigations and audits for possible historic compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.