HomeSecurityexpr-eval: Critical vulnerability exposes AI and NLP apps to risk

expr-eval: Critical vulnerability exposes AI and NLP apps to risk

A serious security vulnerability has been identified in the widely used npm package “expr-eval”, putting thousands of Artificial Intelligence (AI) and Natural Language Processing (NLP). The flaw, officially documented as CVE-2025-12735, could allow malicious users to perform remote code execution (RCE), gaining complete control over systems using the library.

expr-eval AI npm

What is expr-eval and why is it widely used?

expr -eval is a JavaScript library designed to parse and evaluate mathematical expressions in a safer way than eval() . Due to its simplicity and flexibility, it has become a core component in hundreds of projects related to machine learning, computational modeling, and data analysis.

Over 250 other packages directly depend on expr-eval, including oplangchain, a popular JavaScript implementation of the LangChain. This means the vulnerability has a ripple effect across the broader AI ecosystem, affecting tools used in chatbots, agents, LLM pipelines, and custom AI solutions.

How vulnerability works

Researchers at Carnegie Mellon University have discovered that attackers can define arbitrary functions within the parser’s “environment object.” This allows them to inject malicious codethat executes commands at the operating system level.

See also: Whisper Leak: AI steals encrypted conversations

The vulnerability was assessed as having high technical impact in the SSVC (Stakeholder-Specific Vulnerability Categorization) framework , as it offers the attacker full control over the software's behavior and access to critical system information.

The threat is particularly serious for Generative AI and NLP systems, which often run on servers with access to sensitive resources — from databases to APIs and compute nodes. Since these applications accept mathematical expressions from users, the possibility of introducing a malicious command increases exponentially.

expr-eval: Critical vulnerability exposes AI and NLP apps to risk

The solution: Upgrade to the secure version 3.0.0

Developers using expr-eval or its derivative expr-eval-fork are urged to immediately upgrade to version 3.0.0 of expr-eval-fork, which includes critical security fixes.

The new version introduces:

  • Allowlist of safe functions that restricts which functions can be executed.
  • Mandatory registration of custom functionsto prevent the arbitrary addition of dangerous code.
  • Improved security tests, which identify potential breaches before the production stage.

The vulnerability was responsibly by security researcher Jangwoo Choe (UKO) and fixed via GitHub Pull Request #288. Additionally, it was disclosed via GitHub Security Advisory GHSA-jc85-fpwf-qm7xso that organizations can automatically detect the issue via npm audit or GitHub Dependabot.

See also: Elastic Defend for Windows: Vulnerability allows privilege escalation

Impact on the AI ​​ecosystem and companies

The incident highlights how fragile the open source software ecosystem can be, especially when small libraries form the foundation for huge Artificial Intelligence platforms.

A seemingly “innocent” library can develop into a critical point of failure, giving attackers access to AI agents, word or data processing systems , and even cloud infrastructure.

For companies that rely on Node.js or JavaScript pipelines, this vulnerability is a strong reminder of the need for continuous dependency monitoring and regular open source auditing.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

expr-eval: Critical vulnerability exposes AI and NLP apps to risk

Preventive measures and good practices

Experts recommend that organizations implement multi-layered security policies:

  • Use of vulnerability scanners in each release.
  • Sandboxing for modules that evaluate dynamic code.
  • Zero-trust architecture in server-side AI environments.
  • Frequent npm package upgrades and re-checking via GitHub Security Alerts.

In a world where Artificial Intelligence technologies are being integrated everywhere, from chatbots to corporate data pipelines, even a small error in a library can become a backdoor for cyberattacks.

See also: Landfall spyware targeted Samsung Galaxy phones

The researchers' quick response and release of the patch are a positive example of collaboration between the open source community and the security industry. However, the case is a reminder that vigilance remains the most effective protection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS