Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2025-13204
Vulnerability Description
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JavaScript Expression Evaluator 安全漏洞
Vulnerability Description
JavaScript Expression Evaluator是Matthew Crumley个人开发者的一个数学计算器。 JavaScript Expression Evaluator存在安全漏洞,该漏洞源于原型污染,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A