CVE-2025-13204 describes a Prototype Pollution vulnerability in the npm package expr-eval, specifically affecting silentmatt javascript_expression_evaluator. An attacker with access to the express eval interface could leverage this flaw to achieve arbitrary code execution. This vulnerability carries a CVSS score of 7.3 (HIGH), indicating a network-based attack with low attack complexity and potential for low impact on confidentiality, integrity, and availability. The npm expr-eval-fork package resolves this issue. Currently, there is no evidence of active exploitation, nor are there known Metasploit, Nuclei, or ExploitDB modules. Community discussion and media coverage are minimal, suggesting low public awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:silentmatt:javascript_expression_evaluator:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.