ThreatCluster

Critical RCE Vulnerability in expr-eval npm Library Affects AI Applications

First seen 11 Nov 2025, 11:18 UTC GbhackersCyberpress 62

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, tracked as CVE-2025-12735, has been identified in the expr-eval JavaScript library, which is widely used in AI and natural language processing projects. This flaw poses significant risks to server environments and applications that process user input, impacting thousands of projects reliant on this library.