CVE-2026-12866Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 4 mentions (2026-06-23); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-06-23: 4Mentions · 2026-06-24: 1Mentions · 2026-06-28: 1Mentions · 2026-07-01: 1PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-06-23: 4Technical Details · 2026-06-24: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-01: 106-2306-2406-2807-01
Signal classification1 categories
Disclosure
7100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-234
Disclosure4
2026-06-241
Disclosure1
2026-06-281
Disclosure1
2026-07-011
Disclosure1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12866 All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted e… https://www.cve.org/CVERecord?id=CVE-2026-12866

    Post summary

    The text announces a code execution flaw in expr-eval’s toJSFunction API, but it offers no evidence of PoC, exploitation activity, or available patches.

    01000919
    57.7K followersView on X
  • Diego Artiles@dartilesm
    Disclosure

    🚨 expr-eval: critical RCE in every version. CVE-2026-12866, CVSS 9.8. `toJSFunction()` wraps user input in `new Function()`. No sandbox. → All versions vulnerable → CISA: automatable What's your sandboxed expression evaluator?

    Post summary

    The message announces a critical remote code execution vulnerability (CVE-2026-12866) in the expr-eval library affecting all versions, caused by improper use of `new Function()`.

    0000035
    49 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🧮 CVE-2026-12866: All versions of npm's expr-eval are vulnerable to arbitrary code execution via toJSFunction(). Crafted expressions compile into malicious JS. No auth, no interaction needed. CVSS 9.2. Audit your deps now. #nodejs #appsec https://secalerts.co/vulnerability/CVE-2026-12866?utm_campaign=x https://t.co/lHwPUWCKwt

    Post summary

    The tweet announces CVE‑2026‑12866, outlining its arbitrary code execution risk and urging dependency audits, without detailing PoC, patch, or active exploitation.

    00000101
    846 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-12866 affects expr-eval JavaScript library, allowing arbitrary code execution through the toJSFunction API. https://ift.tt/RC0gnGU

    Post summary

    The post announces CVE-2026-12866 affecting the expr-eval JavaScript library, detailing arbitrary code execution via the toJSFunction API, and provides a link that likely references PoC code, but offers no details on exploitation tools, active attacks, patches, or mitigation.

    0000020
    1.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - expr-eval Sandbox Escape via toJSFunction() (CVE-2026-12866) expr-eval (~800K weekly npm downloads) parses user-supplied math expressions. Its toJSFunction() API compiles them into native JS via new Function() — so attacker-controlled expressions become executable code, escaping the sandbox into full RCE. No auth, no user interaction. 👉Affected: all versions of expr-eval; no patched release available.

    Post summary

    An announcement of CVE‑2026‑12866 reveals a sandbox escape in expr‑eval that allows blind remote code execution, with no patch yet released.

    0000079
    226 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-12866 affects expr-eval JavaScript library, allowing arbitrary code execution through the toJSFunction API. https://ift.tt/kEYwOWo

    Post summary

    The post discloses that CVE‑2026‑12866 enables arbitrary code execution through the expr-eval JavaScript library’s toJSFunction API, with no evidence of PoC, exploit, active use, patch, or false‑positive claim.

    0000056
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-12866 All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted e… https://www.cve.org/CVERecord?id=CVE-2026-12866 ----- Traducción: CVE-2026-12866 Tod… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑12866, describing a code‑execution flaw in the expr‑eval package, but offers no PoC, exploit code, evidence of active use, or patch information.

    0000033
    88 followersView on X

Explore more