angular Vulnerabilities and Affected Products
Vulnerabilities associated with Angular.ng-template.
Products
Clear product- angular26 vulnerabilities
- angular-cli5 vulnerabilities
- @nguniversal/common1 vulnerability
- @nguniversal/express-engine1 vulnerability
- Angular.ng-template1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50178HIGH | Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service ExtensionThe Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all rendered content it receives, which enables active elements such as command: URIs. However, the background Angular Language Server process fails to escape or sanitize brackets, raw lin… | CVSS8.7v4.0 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |