Critical Vulnerability Discovered in expr-eval JavaScript Library

Critical Vulnerability Discovered in expr-eval JavaScript Library

First seen 2 Dec 2025, 18:33 UTC Kb.CertBleepingcomputer 28.2

Article Content

Browse articles
ThreatCluster

A critical vulnerability has been identified in the expr-eval JavaScript library, which is widely used for evaluating mathematical expressions in various applications. Discovered by security researcher Jangwoo Choe, this vulnerability (CVE-2025-12735) allows for remote code execution through maliciously crafted input, with a severity rating of 9.8 from CISA. The library has over 800,000 weekly downloads on NPM, making it a significant risk for many developers and applications.