9.8

CVE-2025-12735

CVE-2025-12735

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JorenbroekemaJavascript Expression Evaluator Version3.0.0 SwPlatformnode.js
SilentmattJavascript Expression Evaluator SwPlatformnode.js Version <= 2.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.2% 0.802
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://github.com/silentmatt/expr-eval
Product
https://github.com/jorenbroekema/expr-eval
Product
https://www.npmjs.com/package/expr-eval-fork
Product
https://www.npmjs.com/package/expr-eval
Product
https://github.com/silentmatt/expr-eval/pull/288
Patch
Issue Tracking
https://www.kb.cert.org/vuls/id/263614
Third Party Advisory
https://github.com/jorenbroekema/expr-eval/blob/460b820ba01c5aca6c5d84a7d4f1fa5d1913c67b/test/security.js
Product
https://github.com/advisories/GHSA-jc85-fpwf-qm7x
Third Party Advisory
https://kb.cert.org/vuls/id/263614
Third Party Advisory