Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12735

Опубликовано: 05 нояб. 2025
Источник: redhat
CVSS3: 9.8

Описание

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.

A vulnerability was discovered in the expr-eval npm package, a JavaScript library used to parse and evaluate mathematical expressions. The issue allows an attacker to define arbitrary functions within the context object used by the parser's evaluate() method. By providing maliciously crafted input, an attacker can exploit this flaw to inject and execute arbitrary system-level commands on the host system. This could lead to the execution of malicious code.

Отчет

Although expr-eval is listed as a bundled dependency in grafana-pcp in RHEL 8, the library is not present in the compiled JavaScript bundle and the vulnerable code does not execute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8grafana-pcpNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-917

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
10 месяцев назад

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted context object or use MEMBER of the context object into the evaluate() function and trigger arbitrary code execution.

github
10 месяцев назад

expr-eval does not restrict functions passed to the evaluate function

CVSS3: 9.8
fstec
10 месяцев назад

Уязвимость функции estimate() библиотеки expr-eval, позволяющая нарушителю выполнить произвольный код

9.8 Critical

CVSS3