High severity8.7NVD Advisory· Published Jan 24, 2020· Updated Jun 17, 2026
CVE-2020-5219
CVE-2020-5219
Description
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-expressions in the browser, an attacker could run any browser script when the application code calls expressions.compile(userControlledInput). If running angular-expressions on the server, an attacker could run any Javascript expression, thus gaining Remote Code Execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
angular-expressionsnpm | < 1.0.1 | 1.0.1 |
Affected products
3cpe:2.3:a:peerigon:angular-expressions:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:peerigon:angular-expressions:*:*:*:*:*:node.js:*:*range: <1.0.1
- (no CPE)range: < 1.0.1
Patches
Vulnerability mechanics
References
5- github.com/peerigon/angular-expressions/commit/061addfb9a9e932a970e5fcb913d020038e65667nvdPatchWEB
- blog.angularjs.org/2016/09/angular-16-expression-sandbox-removal.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-hxhm-96pp-2m43ghsaADVISORY
- github.com/peerigon/angular-expressions/security/advisories/GHSA-hxhm-96pp-2m43nvdMitigationThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-5219ghsaADVISORY
News mentions
0No linked articles in our index yet.