CVE-2026-50178
angular angular, Angular.ng-template, angular language service
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the tooltip Markdown renderer with the isTrusted: true option (located in client/src/client.ts). This setting instructs VS Code to trust all rendered content it receives, which enables active elements such as command: URIs. However, the background Angular Language Server process fails to escape or sanitize brackets, raw links, and control characters from JSDoc strings before forwarding the hover Markdown content (locat...
- CVSS
- 8.7
- EPSS
- 0.27% 19.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23