CVE-2025-12735 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However,…
Critical CVSS: 9.8

CVE-2025-12735

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.
Vendor
Jorenbroekema
Product
Javascript Expression Evaluator
CWE
CWE-94
Yayın Tarihi
2025-11-05 01:15:33
Güncelleme
2026-02-10 17:33:24
Source Identifier
cret@cert.org
KEV Date Added
-

Kategoriler

Referanslar