PT-2025-46975 · Pypi · Expr-Eval

CVE-2025-13204

·

Publicado

2025-11-14

·

Atualizado

2026-06-04

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions npm package expr-eval (affected versions not specified)
Description The npm package expr-eval is susceptible to a Prototype Pollution issue. An attacker who can access the express eval interface may leverage the JavaScript prototype-based inheritance model to potentially achieve arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13204
GHSA-8GW3-RXH4-V6JX
RHSA-2026:0140

Produtos afetados

Expr-Eval