{"id":"CVE-2025-13204","summary":"CVE-2025-13204","details":"npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.","aliases":["GHSA-8gw3-rxh4-v6jx"],"modified":"2026-08-12T03:30:38.683330998Z","published":"2025-11-14T17:02:39.529Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13204.json","cna_assigner":"certcc"},"references":[{"type":"WEB","url":"https://github.com/SECCON/SECCON2022_final_CTF/blob/main/jeopardy/web/babybox/solver/solver.py"},{"type":"WEB","url":"https://www.npmjs.com/package/expr-eval-fork"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13204.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13204"},{"type":"ADVISORY","url":"https://www.huntr.dev/bounties/1-npm-expr-eval/"},{"type":"FIX","url":"https://github.com/silentmatt/expr-eval/pull/252/files"},{"type":"PACKAGE","url":"https://github.com/jorenbroekema/expr-eval"},{"type":"PACKAGE","url":"https://github.com/silentmatt/expr-eval"},{"type":"EVIDENCE","url":"https://github.com/vladko312/extras/blob/f549d505af300fd74a01b46fab2102990ff1c14d/expr-eval.py"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/silentmatt/expr-eval","events":[{"introduced":"0"},{"last_affected":"9f40d2b0367f551bd2c07a6c7d2e06d8943cd7c3"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"2.0.2"}]}}],"versions":["v2.0.2","v2.0.1","v2.0.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.1","v1.0.0","v1.0.0-rc.3","v0.12.0","v0.11.0","v0.10.1","v0.10.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-13204.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}