Showing 1 vulnerability on this page for Angular.ng-template

Signals CISA KEV Ransomware Nuclei
angular vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service Extension

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all rendered content it receives, which enables active elements such as command: URIs. However, the background Angular Language Server process fails to escape or sanitize brackets, raw lin

CWE-79CWE-94Jun 22, 2026
CVSS8.7v4.0EPSS0.275%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX