Popular JavaScript library expr-eval vulnerable to RCE flaw
ID: 2ea13901-fccd-5851-9c82-8404cc6fe743
STIX ID: report--2ea13901-fccd-5851-9c82-8404cc6fe743
Feed Name: Bleeping Computer
Threat Score
A critical RCE vulnerability (CVE-2025-12735, CVSS 9.8) was found in the expr-eval JavaScript expression parser allowing attacker-supplied function objects in the Parser.evaluate context to be invoked, giving potential full control or data disclosure on affected systems; the issue affects both the original library and its fork, and users are advised to migrate to expr-eval-fork v3.0.0 which contains a fix enforcing an allowlist and safer function registration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
