Vulnerabilities (CVE)

Filtered by vendor Silentmatt Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-13204 1 Silentmatt 1 Javascript Expression Evaluator 2026-01-08 N/A 7.3 HIGH
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.