Skip to content
ThreatCluster

Critical RCE Vulnerability in expr-eval npm Library Affects AI Applications

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical remote code execution vulnerability, tracked as CVE-2025-12735, has been identified in the expr-eval JavaScript library. This library is widely used in AI and natural language processing projects, impacting thousands of applications that rely on it for mathematical expression evaluation. The flaw poses significant risks to server environments and AI-powered applications that process user input.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-12735 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed