Security Advisory
CVE-2025-13204
7.3
HIGH
Vulnerability Description
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Published Date
November 14, 2025
Official Source
NIST NVD Advisory