Skip to content

CVE-2025-12735

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 7, 2025
Last Seen
November 11, 2025
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical remote code execution vulnerability, tracked as CVE-2025-12735, has been identified in the expr-eval JavaScript library, which is widely used in AI and natural language processing projects. This flaw poses significant risks to server environments and applications that process user input,...

A critical remote code execution vulnerability, tracked as CVE-2025-12735, has been identified in the expr-eval JavaScript library. This library is widely used in AI and natural language processing projects, impacting thousands of applications that rely on it for mathematical expression evaluation....

A critical vulnerability has been identified in the expr-eval JavaScript library, which has over 800,000 weekly downloads on NPM. This vulnerability, tracked as CVE-2025-12735, allows for remote code execution through maliciously crafted input, posing significant risks to applications that utilize t...

A critical vulnerability has been identified in the expr-eval JavaScript library, which is widely used for evaluating mathematical expressions in various applications. Discovered by security researcher Jangwoo Choe, this vulnerability (CVE-2025-12735) allows for remote code execution through malicio...

Public Exploits

Checking GitHub for proof-of-concept code…