ThreatCluster

Critical RCE Vulnerability in expr-eval npm Library Affects AI Applications

First seen 2 Dec 2025, 18:33 UTC GbhackersCyberpress 49

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, tracked as CVE-2025-12735, has been identified in the expr-eval JavaScript library. This library is widely used in AI and natural language processing projects, impacting thousands of applications that rely on it for mathematical expression evaluation. The flaw poses significant risks to server environments and AI-powered applications that process user input.