CVE-2026-50178
angular angular, Angular.ng-template, angular language service 취약점
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all rendered content it receives, which enables active elements such as command: URIs. However, the background Angular Language Server process fails to escape or sanitize brackets, raw links, and control characters from JSDoc strings before forwarding the hover Markdown content (locat...
- 대응 우선순위
- 점검
- CVSS
- 8.7
- EPSS
- 0.27% 백분위 19.7% · 2026.07.31 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.23