expr-eval — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 10, 2025
Last Seen
November 10, 2025

expr-eval is a JavaScript expression evaluation library used in Node.js environments to parse and compute dynamic expressions, including in AI and NLP workflows.

Overview

expr-eval is a JavaScript expression evaluation library used in Node.js environments to parse and compute dynamic expressions, including in AI and NLP workflows. Recent reports describe a critical remote code execution (RCE) vulnerability in expr-eval, making exposed applications susceptible to arbitrary code execution if exploited. This underscores the security risk of evaluating user-supplied expressions and the importance of dependency hygiene in modern JS stacks.

Related Threat Clusters

Recent Intelligence Reports

  • Popular npm Library Used in AI and NLP Projects Exposes Systems to RCE — Gbhackers · November 10, 2025

CVSS v3.1 Breakdown