CVE-2025-12735
CVE-2025-12735

Currently unrated

Key Information:

Vendor

Silentmatt

Vendor
CVE Published:
5 November 2025

What is CVE-2025-12735?

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted variables object into the evaluate() function and trigger arbitrary code execution.

Affected Version(s)

expr-eval 0 <= 2.0.2

expr-eval-fork 0 <= 2.0.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was reported by Jangwoo Choe (UKO)
.
CVE-2025-12735 : Arbitrary Code Execution Vulnerability in expr-eval Library by SilentMatt