A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-12735, has been discovered in the widely used JavaScript library expr-eval and its actively maintained fork, expr-eval-fork. The flaw, identified by security researcher Jangwoo Choe, arises from insufficient validation of variables or context objects passed to the Parser.evaluate() function, allowing attackers to inject malicious function objects and gain total control over affected systems. The vulnerability impacts both the original library and its fork, which together account for hundreds of thousands of weekly downloads and are used in a variety of applications, including online calculators, educational tools, financial software, and AI/NLP systems.
CERT Coordination Center (CERT/CC) and CISA have rated the issue as critical, with a CVSS score of 9.8, warning that exploitation could lead to full system compromise or disclosure of all information on the affected system. Users are strongly advised to upgrade to expr-eval-fork version 3.0.0, which addresses the vulnerability by implementing a safe function allowlist, a custom function registration system, and improved test coverage. The security fix is essential for all projects relying on either the original or forked versions of expr-eval to prevent exploitation in production environments.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A remote code execution flaw affecting the popular expr-eval JavaScript library was publicly disclosed. Multiple outlets reported the issue as enabling possible RCE in applications using the library.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.