Product
silentmatt javascript expression evaluator
2 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-13204
CVE-2025-12735
all versions
npm package
expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript<= 2.0.2
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with us