Critical Vulnerability Found In Popular NPM JavaScript Tool With 800k Weekly Downloads

A popular tool available via NPM has been found to contain a critical vulnerability which may allow for remote code execution.

Published on Nov 11, 2025
Joel Witts Written by Joel Witts
Popular NPM JavaScript Tool With 800k Weekly Downloads Vulnerable To Critical Vulnerability

A popular expression evaluator library contains a critical vulnerability (CVSS 9.8) that could allow remote code execution and complete system compromise.

The JavaScript Expression Evaluator package receives about 800,000 weekly downloads and is used in roughly 250 projects, including calculators, learning apps, and AI tools. 

The vulnerability stems from improper sandboxing in the evaluate() and compile() functions. Due to insufficient input validation, attackers can inject crafted expressions that escape the sandbox and execute arbitrary code.

According to a Wiz advisory this poses a significant security risk, as it could potentially allow full compromise of any application using the vulnerable library.

detailed breakdown of the vulnerability was published by the CERT Coordination Center over the weekend.

The security researchers who found the vulnerability attempted to reach the original developers, but were unable to do so, Wiz reports.

A community-maintained fork, expr-eval-fork, has been released with a patch. Developers using expr-eval should migrate immediately.

“Users are advised to switch to the patched version expr-eval-fork available on NPM (GitHub PRNPM Fork),” Wiz recommends.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.