Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-12866

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

EPSS

Процентиль: 40%
0.00496
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 4.2
redhat
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

CVSS3: 9.8
github
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

EPSS

Процентиль: 40%
0.00496
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94
CWE-94