Vulnerability record · CVE-2021-21277 · published 1 February 2021
CVE-2021-21277: Peerigon angular-expressions injection vulnerability
Peerigon · Angular Expressions
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControlledInput)" where "userControlledInput" is text that comes from user input. The security of the package could be bypassed by using a more complex payload, using a ".constructor.constructor" technique. In terms of impact: If running angular-expressions in the browser, an attacker could run any browser script when the application code calls expressions.compile(userControlledInput). If running angular-expressions on the server, an attacker could run any Javascript expression, thus gaining Remote Code Execution. This is fixed in version 1.1.2 of angular-expressions A temporary workaround might be either to disable user-controlled input that will be fed into angular-expressions in your application or allow only following characters in the userControlledInput.
Description
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControlledInput)" where "userControlledInput" is text that comes from user input. The security of the package could be bypassed by using a more complex payload, using a ".constructor.constructor" technique. In terms of impact: If running angular-expressions in the browser, an attacker could run any browser script when the application code calls expressions.compile(userControlledInput). If running angular-expressions on the server, an attacker could run any Javascript expression, thus gaining Remote Code Execution. This is fixed in version 1.1.2 of angular-expressions A temporary workaround might be either to disable user-controlled input that will be fed into angular-expressions in your application or allow only following characters in the userControlledInput.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blog.angularjs.org/2016/09/angular-16-expression-sandbox-removal.html | Broken LinkVendor Advisory |
| https://github.com/peerigon/angular-expressions/commit/07edb62902b1f6127b3dcc013da61c6316dd0bf1 | PatchThird Party Advisory |
| https://github.com/peerigon/angular-expressions/security/advisories/GHSA-j6px-jwvv-vpwq | Vendor Advisory |
| https://www.npmjs.com/package/angular-expressions | Product |
| http://blog.angularjs.org/2016/09/angular-16-expression-sandbox-removal.html | Broken LinkVendor Advisory |
| https://github.com/peerigon/angular-expressions/commit/07edb62902b1f6127b3dcc013da61c6316dd0bf1 | PatchThird Party Advisory |
| https://github.com/peerigon/angular-expressions/security/advisories/GHSA-j6px-jwvv-vpwq | Vendor Advisory |
| https://www.npmjs.com/package/angular-expressions | Product |
Track CVE-2021-21277 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21277), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.