Diego Artiles[verified]@dartilesmDisclosure
The message announces a critical remote code execution vulnerability (CVE-2026-12866) in the expr-eval library affecting all versions, caused by improper use of `new Function()`.
Israel[verified]@f1tym1Disclosure
The post announces CVE-2026-12866 affecting the expr-eval JavaScript library, detailing arbitrary code execution via the toJSFunction API, and provides a link that likely references PoC code, but offers no details on exploitation tools, active attacks, patches, or mitigation.
Upwind Security MDR[verified]@UpwindMDRDisclosure
An announcement of CVE‑2026‑12866 reveals a sandbox escape in expr‑eval that allows blind remote code execution, with no patch yet released.
Israel[verified]@f1tym1Disclosure
The post discloses that CVE‑2026‑12866 enables arbitrary code execution through the expr-eval JavaScript library’s toJSFunction API, with no evidence of PoC, exploit, active use, patch, or false‑positive claim.
CVE@CVEnewDisclosure
The text announces a code execution flaw in expr-eval’s toJSFunction API, but it offers no evidence of PoC, exploitation activity, or available patches.
SecAlerts@SecAlertsCoDisclosure
The tweet announces CVE‑2026‑12866, outlining its arbitrary code execution risk and urging dependency audits, without detailing PoC, patch, or active exploitation.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE‑2026‑12866, describing a code‑execution flaw in the expr‑eval package, but offers no PoC, exploit code, evidence of active use, or patch information.