
LOOK BACK — A 2009 math parser sold as "safer than eval" became the calculator tool in LLM agent chains. CVE-2025-12735 was a 9.8 RCE in expr-eval: the evaluator ran any function in the variables object. Ten months on, there is still no fixed version of the package. https://t.co/cdXXRf7JwN
Post summary
The tweet reports that CVE‑2025‑12735 is a severe RCE flaw in the expr‑eval package, remains unpatched after ten months, and highlights the vulnerability’s high impact.

