Количество 3
Количество 3
CVE-2025-13204
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
CVE-2025-13204
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
GHSA-8gw3-rxh4-v6jx
expr-eval vulnerable to Prototype Pollution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-13204 npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
CVE-2025-13204 npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-8gw3-rxh4-v6jx expr-eval vulnerable to Prototype Pollution | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад |
Уязвимостей на страницу