PT-2025-46975 · Pypi · Expr-Eval

Published

2025-11-14

·

Updated

2026-01-24

·

CVE-2025-13204

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions npm package expr-eval (affected versions not specified)
Description The npm package expr-eval is susceptible to a Prototype Pollution issue. An attacker who can access the express eval interface may leverage the JavaScript prototype-based inheritance model to potentially achieve arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2025-13204
GHSA-8GW3-RXH4-V6JX
RHSA-2026:0140

Affected Products

Expr-Eval