CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Configurations

No configuration.

History

14 Nov 2025, 21:15

Type Values Removed Values Added
CWE CWE-1321
References
  • () https://github.com/SECCON/SECCON2022_final_CTF/blob/main/jeopardy/web/babybox/solver/solver.py -
  • () https://github.com/silentmatt/expr-eval/pull/252/files -
  • () https://github.com/vladko312/extras/blob/f549d505af300fd74a01b46fab2102990ff1c14d/expr-eval.py -
  • () https://www.huntr.dev/bounties/1-npm-expr-eval/ -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

14 Nov 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-14 17:16

Updated : 2025-11-18 14:06


NVD link : CVE-2025-13204

Mitre link : CVE-2025-13204

CVE.ORG link : CVE-2025-13204


JSON object : View

Products Affected

No product.

CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')