CVE-2025-13204 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance m…
High CVSS: 7.3

CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Vendor
Silentmatt
Product
Javascript Expression Evaluator
CWE
CWE-1321
Yayın Tarihi
2025-11-14 17:16:01
Güncelleme
2026-01-08 18:28:13
Source Identifier
cret@cert.org
KEV Date Added
-

Kategoriler

Referanslar