Skip to content
Critical Vulnerability Discovered in expr-eval JavaScript Library

Critical Vulnerability Discovered in expr-eval JavaScript Library

First seen 11 Nov 2025, 11:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A critical vulnerability has been identified in the expr-eval JavaScript library, which has over 800,000 weekly downloads on NPM. This vulnerability, tracked as CVE-2025-12735, allows for remote code execution through maliciously crafted input, posing significant risks to applications that utilize this library. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has rated the severity of this issue as critical, with a score of 9.8.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-12735 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed