Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12866

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

A flaw was found in expr-eval. A remote attacker can exploit this vulnerability by supplying crafted expressions to the toJSFunction() API. These expressions are then compiled into native code using new Function(), allowing the attacker to execute arbitrary JavaScript code. This can lead to arbitrary code execution within the application's context, potentially compromising the system.

Отчет

RHEL AI 3.4 bootc images ship expr-eval@2.0.2 as a dependency of @langchain/community. The only identified consumer is the LangChain Calculator tool, which calls Parser.evaluate() and does not invoke toJSFunction(). CVE-2026-12866 affects only the toJSFunction() API. No other npm package in the image depends on expr-eval. For this reason the issue is rated Low for RHEL AI.

Меры по смягчению последствий

LangChainJS already replaced expr-eval with math-expression-evaluator in a later @langchain/community release (fix for CVE-2025-12735). Bootc owners should bump @langchain/community to a version that no longer bundles expr-eval, which removes the dead dependency entirely.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2491633expr-eval: expr-eval: Code Execution via crafted expressions in toJSFunction() API

EPSS

Процентиль: 40%
0.00496
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

CVSS3: 9.8
github
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

EPSS

Процентиль: 40%
0.00496
Низкий

4.2 Medium

CVSS3