logo

Angular Language Service Extension Flaws Allow Remote Code Execution

ID: ab08840c-7698-527f-8d6f-7af73ee56b0f

STIX ID: report--ab08840c-7698-527f-8d6f-7af73ee56b0f

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Divya

...
...

Multiple high-severity remote code execution vulnerabilities were discovered in the Angular Language Service VS Code extension (patched in version 21.2.4). Attackers can exploit a JSDoc hover Markdown command injection and an unsafe tsdk loading mechanism to execute arbitrary code — the latter can run silently during workspace initialization and both bypass VS Code Workspace Trust. Developers are advised to upgrade immediately, review workspace settings, avoid untrusted repositories, and enforce strict trust policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.