CVE-2025-13204 PUBLISHED

CVE-2025-13204

Assigner: certcc
Reserved: 14.11.2025 Published: 14.11.2025 Updated: 14.11.2025

npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

Product Status

Vendor silentmatt
Product expr-eval
Versions
  • affected from 0 to 2.0.2 (incl.)

References

Problem Types

  • CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')