CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2025-11-14 17:16

Updated : 2026-01-08 18:28


NVD link : CVE-2025-13204

Mitre link : CVE-2025-13204

CVE.ORG link : CVE-2025-13204


JSON object : View

Products Affected

silentmatt

  • javascript_expression_evaluator
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')