CVE-2025-12735
ADVISORY - githubSummary
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted variables object into the evaluate() function and trigger arbitrary code execution.
Common Weakness Enumeration (CWE)
Improper Control of Generation of Code ('Code Injection')
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
NIST
3.9
CVSS SCORE
9.8criticalGitHub
-
CVSS SCORE
8.6highRed Hat
3.9
CVSS SCORE
9.8criticalminimos
MINI-5f9w-64w5-fj29
-
minimos
MINI-5q92-fx8f-48h8
-
minimos
MINI-67pm-4g9j-7gqw
-
minimos
MINI-6p87-g8qj-h3gp
-
minimos
MINI-g74w-vc85-mmh7
-
minimos
MINI-v8c7-mrhx-p5fh
-
minimos
MINI-wg3m-w8r3-vjpp
-