CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:*

History

08 Jan 2026, 18:28

Type Values Removed Values Added
CPE cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:*
First Time Silentmatt
Silentmatt javascript Expression Evaluator
References () https://github.com/SECCON/SECCON2022_final_CTF/blob/main/jeopardy/web/babybox/solver/solver.py - () https://github.com/SECCON/SECCON2022_final_CTF/blob/main/jeopardy/web/babybox/solver/solver.py - Product
References () https://github.com/jorenbroekema/expr-eval - () https://github.com/jorenbroekema/expr-eval - Product
References () https://github.com/silentmatt/expr-eval - () https://github.com/silentmatt/expr-eval - Product
References () https://github.com/silentmatt/expr-eval/pull/252/files - () https://github.com/silentmatt/expr-eval/pull/252/files - Patch, Issue Tracking
References () https://github.com/vladko312/extras/blob/f549d505af300fd74a01b46fab2102990ff1c14d/expr-eval.py - () https://github.com/vladko312/extras/blob/f549d505af300fd74a01b46fab2102990ff1c14d/expr-eval.py - Product
References () https://www.huntr.dev/bounties/1-npm-expr-eval/ - () https://www.huntr.dev/bounties/1-npm-expr-eval/ - Exploit, Third Party Advisory
References () https://www.npmjs.com/package/expr-eval-fork - () https://www.npmjs.com/package/expr-eval-fork - Product

14 Nov 2025, 21:15

Type Values Removed Values Added
CWE CWE-1321
References
  • () https://github.com/SECCON/SECCON2022_final_CTF/blob/main/jeopardy/web/babybox/solver/solver.py -
  • () https://github.com/silentmatt/expr-eval/pull/252/files -
  • () https://github.com/vladko312/extras/blob/f549d505af300fd74a01b46fab2102990ff1c14d/expr-eval.py -
  • () https://www.huntr.dev/bounties/1-npm-expr-eval/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

14 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-14 17:16

Updated : 2026-01-08 18:28


NVD link : CVE-2025-13204

Mitre link : CVE-2025-13204

CVE.ORG link : CVE-2025-13204


JSON object : View

Products Affected

silentmatt

  • javascript_expression_evaluator
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')