CVE 7.3 HIGH

CVE-2025-13204_CVE-2025-13204

7.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

Basic Information

ID CVE-2025-13204
Source certcc
Published Nov 14, 2025 at 17:02
Modified Nov 14, 2025 at 20:41

Affected Product

Vendor silentmatt
Product expr-eval
Affected Versions silentmatt expr-eval 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.