CVE-2024-54152 is a critical arbitrary code execution vulnerability in Angular Expressions, the standalone expression engine for the AngularJS framework. Versions prior to 1.4.3 improperly enforce sandbox restrictions, allowing a crafted malicious expression to escape the intended execution boundary. Successful exploitation enables evaluation of attacker-controlled code in the underlying runtime environment, resulting in arbitrary code execution on the host system. The issue is described as a sandbox escape in the expression evaluation logic and was fixed in Angular Expressions 1.4.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small proof-of-concept exploit plus a deliberately vulnerable demo application for CVE-2024-54152 in angular-expressions. Structure: README with usage notes; two client exploit scripts (Go and Python); Dockerfile to build/run the vulnerable service; vuln_app/config.json declaring angular-expressions 1.4.2 and Express dependencies; and vuln_app/server.js implementing the vulnerable endpoint. The vulnerable app listens on port 8080 and exposes POST /parse, which reads JSON field 'expression', passes it to angularExpressions.compile(), then executes the compiled expression with no sandbox hardening. Both poc.go and poc.py send a JSON payload containing a malicious expression that abuses __proto__.toString.constructor(...) to reach the JavaScript Function constructor, require Node's child_process module, run the 'id' command, and return its output. This is a real exploit POC rather than a detector: it demonstrates remote web-triggered arbitrary code execution against applications that evaluate attacker-controlled angular-expressions input on the server side.
This repository is a proof-of-concept (POC) exploit for CVE-2024-54152, a sandbox escape vulnerability in the 'angular-expressions' Node.js module (version 1.4.2). The repository contains a minimal vulnerable Node.js application (vuln_app/server.js) that exposes a '/parse' HTTP POST endpoint, which evaluates user-supplied Angular expressions without proper sandboxing. The Dockerfile and config.json facilitate easy deployment of the vulnerable app. Two exploit scripts (poc.go and poc.py) are provided to send a malicious payload to the /parse endpoint. The payload leverages prototype pollution and JavaScript's Function constructor to execute arbitrary system commands (e.g., 'id') on the server. The exploit demonstrates remote code execution by returning the command output in the HTTP response. The repository is structured for demonstration and educational purposes, with clear separation between the vulnerable app and the exploit scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Предыдущая RCE-уязвимость sandbox escape в angular-expressions, упомянутая как часть истории повторяющихся обходов sandbox в этом пакете.
A critical sandbox-escape vulnerability in Angular Expressions (used with AngularJS) that allows attackers to craft malicious expressions leading to arbitrary code execution on the underlying system.
A critical arbitrary code execution vulnerability in Peerigon Angular-Expressions caused by sandbox escape via malicious expressions in versions prior to 1.4.3.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.