Bleepingcomputer
Critical Vulnerability Discovered in expr-eval JavaScript Library
First seen 2 Dec 2025, 18:33 UTC
•
•28.2
Export
Article Content
Browse articles
A critical vulnerability has been identified in the expr-eval JavaScript library, which is widely used for evaluating mathematical expressions in various applications. Discovered by security researcher Jangwoo Choe, this vulnerability (CVE-2025-12735) allows for remote code execution through maliciously crafted input, with a severity rating of 9.8 from CISA. The library has over 800,000 weekly downloads on NPM, making it a significant risk for many developers and applications.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Critical Vulnerability in Cline Kanban Exposes AI Coding Agents to Hijacking
North Korean Malware Targets Crypto Developers via NPM Packages
Google Releases Emergency Patch for Actively Exploited Chrome Zero-Day Vulnerability
State-Linked Cyber Threats Intensify Amid AI Advancements
Wikimedia Foundation Targeted by Self-Propagating JavaScript Worm