REDHAT-BUG-2415051: High severity npm/expr-eval vulnerability
Published Nov 14, 2025
·Updated
npm package expr-eval is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
Affected Software
1 affected component
npm/expr-eval
Event History
Nov 14, 2025
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2415051?
The severity of REDHAT-BUG-2415051 is rated high with a score of 7.
2
What vulnerability does REDHAT-BUG-2415051 address?
REDHAT-BUG-2415051 addresses a Prototype Pollution vulnerability in the npm package expr-eval.
3
How can I mitigate REDHAT-BUG-2415051?
You can mitigate REDHAT-BUG-2415051 by using the npm package expr-eval-fork which resolves the issue.
4
What is the risk associated with REDHAT-BUG-2415051?
The risk associated with REDHAT-BUG-2415051 is a potential arbitrary code execution through the express eval interface.
5
When was REDHAT-BUG-2415051 published?
REDHAT-BUG-2415051 was published on November 14, 2025.