Bleepingcomputer
Critical Vulnerability Discovered in expr-eval JavaScript Library
First seen 11 Nov 2025, 11:18 UTC
•
•79% similarity
•41.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A critical vulnerability has been identified in the expr-eval JavaScript library, which has over 800,000 weekly downloads on NPM. This vulnerability, tracked as CVE-2025-12735, allows for remote code execution through maliciously crafted input, posing significant risks to applications that utilize this library. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has rated the severity of this issue as critical, with a score of 9.8.
ThreatCluster AI