Critical Vulnerability Discovered in expr-eval JavaScript Library

Critical Vulnerability Discovered in expr-eval JavaScript Library

First seen 11 Nov 2025, 11:18 UTC Kb.CertBleepingcomputer 79% similarity 41.3

Article Content

Browse articles
ThreatCluster

A critical vulnerability has been identified in the expr-eval JavaScript library, which has over 800,000 weekly downloads on NPM. This vulnerability, tracked as CVE-2025-12735, allows for remote code execution through maliciously crafted input, posing significant risks to applications that utilize this library. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has rated the severity of this issue as critical, with a score of 9.8.

ThreatCluster AI

Community

Browse all →

Tracked Entities in This Story