Silentmatt maintains a JavaScript expression-evaluation library that, despite narrow scope, sits in the parsing and computation path of applications accepting user-supplied expressions, creating a direct injection surface. The observed vulnerabilities center on code injection and prototype pollution—weaknesses endemic to dynamic script evaluation and object-property manipulation in JavaScript contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Silentmatt over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12735CRITICAL The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient | Nov 5, 2025 | 9.8 | 37 | NO | NO |
CVE-2025-13204HIGH npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbi | Nov 14, 2025 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Silentmatt.
Media articles that mention a CVE ID that affects a product developed by Silentmatt — matched by CVE ID, not by vendor name.