logo

Popular JavaScript library expr-eval vulnerable to RCE flaw

ID: 2ea13901-fccd-5851-9c82-8404cc6fe743

STIX ID: report--2ea13901-fccd-5851-9c82-8404cc6fe743

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-11-10

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A critical RCE vulnerability (CVE-2025-12735, CVSS 9.8) was found in the expr-eval JavaScript expression parser allowing attacker-supplied function objects in the Parser.evaluate context to be invoked, giving potential full control or data disclosure on affected systems; the issue affects both the original library and its fork, and users are advised to migrate to expr-eval-fork v3.0.0 which contains a fix enforcing an allowlist and safer function registration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.