Widely used JavaScript expression parser and evaluator "expr-eval" has been impacted with a critical security issue, tracked as CVE-2025-12735, which could be leveraged to enable remote code execution, according to BleepingComputer.Both the original expr-eval issued in 2019 and the current expr-eval-fork version are affected by the flaw, which stems from the library's lack of validation for variables or context objects given to the Parser.evaluate() function, said the CERT Coordination Center in a weekend advisory.Such a bug, which was identified by security researcher Jangwoo Choe, "gives the adversary total control over the behavior of the software or total disclosure of all information on the affected system," CERT/CC added. All users of the impacted instances have been advised to upgrade to expr-eval-fork version 3.0.0, which resolves the vulnerability by implementing not only a safe function allowlist and a system for registering custom functions but also strengthening test coverage.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
