HIGH 7.3 npm

expr-eval vulnerable to Prototype Pollution

GHSA-8gw3-rxh4-v6jx · CVE-2025-13204

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes