{"id":"CVE-2021-21277","details":"angular-expressions is \"angular's nicest part extracted as a standalone module for the browser and node\". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call \"expressions.compile(userControlledInput)\" where \"userControlledInput\" is text that comes from user input. The security of the package could be bypassed by using a more complex payload, using a \".constructor.constructor\" technique. In terms of impact: If running angular-expressions in the browser, an attacker could run any browser script when the application code calls expressions.compile(userControlledInput). If running angular-expressions on the server, an attacker could run any Javascript expression, thus gaining Remote Code Execution. This is fixed in version 1.1.2 of angular-expressions A temporary workaround might be either to disable user-controlled input that will be fed into angular-expressions in your application or allow only following characters in the userControlledInput.","aliases":["GHSA-j6px-jwvv-vpwq"],"modified":"2026-07-09T01:25:35.780579Z","published":"2021-02-01T15:15:13.340Z","references":[{"type":"WEB","url":"https://www.npmjs.com/package/angular-expressions"},{"type":"ADVISORY","url":"http://blog.angularjs.org/2016/09/angular-16-expression-sandbox-removal.html"},{"type":"ADVISORY","url":"https://github.com/peerigon/angular-expressions/security/advisories/GHSA-j6px-jwvv-vpwq"},{"type":"FIX","url":"https://github.com/peerigon/angular-expressions/commit/07edb62902b1f6127b3dcc013da61c6316dd0bf1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/peerigon/angular-expressions","events":[{"introduced":"0"},{"fixed":"3e4f0b437c33f57ba8f13e4197242740ff555aa0"},{"fixed":"07edb62902b1f6127b3dcc013da61c6316dd0bf1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.1.2"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:peerigon:angular-expressions:*:*:*:*:*:node.js:*:*"}}],"versions":["v1.1.1","v1.1.0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21277.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}