CVE-2025-13204: Silentmatt JavaScript Expression Evaluator

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

Affected products

  • Silentmatt JavaScript Expression Evaluator: any version

Published 2025-11-14. Last modified 2026-10-07.