CVE-2025-13204: High severity npm expr-eval vulnerability
npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13204?
CVE-2025-13204 has a high severity rating due to the potential for arbitrary code execution through prototype pollution.
How do I fix CVE-2025-13204?
To fix CVE-2025-13204, replace the vulnerable npm package `expr-eval` with the patched version `expr-eval-fork`.
Who is affected by CVE-2025-13204?
Any application utilizing the npm package `expr-eval` is potentially affected by CVE-2025-13204.
What types of attacks can CVE-2025-13204 enable?
CVE-2025-13204 can enable attackers to execute arbitrary code by exploiting prototype pollution within the application.
Is CVE-2025-13204 present in all versions of expr-eval?
Yes, all versions of the `expr-eval` package are susceptible to CVE-2025-13204.