CVE-2025-12735Disclosure(jorenbroekema / javascript_expression_evaluator)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch jorenbroekema javascript_expression_evaluator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • javascript_expression_evaluator

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-09-03)
  • 3 total mentions across 2 days

Affected systems

Products
javascript_expression_evaluator

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-22: 1Mentions · 2026-09-03: 2Patch / Workaround · 2026-09-03: 1Technical Details · 2026-02-22: 1Technical Details · 2026-09-03: 102-2209-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-221
Disclosure1
2026-09-032
Disclosure1Patch1
Full discourse3 posts
  • CVE Brief@DailyCVEBrief
    Disclosure

    LOOK BACK — A 2009 math parser sold as "safer than eval" became the calculator tool in LLM agent chains. CVE-2025-12735 was a 9.8 RCE in expr-eval: the evaluator ran any function in the variables object. Ten months on, there is still no fixed version of the package. https://t.co/cdXXRf7JwN

    Post summary

    The tweet reports that CVE‑2025‑12735 is a severe RCE flaw in the expr‑eval package, remains unpatched after ten months, and highlights the vulnerability’s high impact.

    1000054
    31 followersView on X
  • Codve.ai@CodveAi
    Disclosure

    🛡️ Codve caught CVE-2025-12735 in expr-eval (800k downloads/week) The bug: new Function() allows arbitrary code execution Codve flagged it in 3ms: "Safety violation: Disallowed constructor: new Function()" How many of your dependencies have this? 🧵

    Post summary

    Codve identified CVE-2025-12735 in the expr-eval library, noting that the use of new Function() permits arbitrary code execution, but no PoC, exploit, or patch is mentioned.

    1000059
    64 followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    Full Look Back writeup: the README line that flipped the threat model in 2016, a fix merged in 2021 and never released, CERT/CC shipping the patch through a fork, and why half a million weekly installs stay unpatched: https://cvebrief.com/cve/CVE-2025-12735/ https://t.co/7ynhyWG6fC

    Post summary

    The tweet references a write‑up about CVE‑2025‑12735, noting a 2021‑merged fix that was never released and a CERT/CC forked patch, explaining why many weekly installs remain unpatched.

    0000030
    31 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjorenbroekemajavascript_expression_evaluator3.0.0node.js-
Appsilentmattjavascript_expression_evaluator-node.js-

Explore more