Topic: npm downloads

  • Critical RCE Flaw Found in Popular expr-eval JavaScript Library

    Critical RCE Flaw Found in Popular expr-eval JavaScript Library

    A critical remote code execution vulnerability (CVE-2025-12735) has been found in the widely used expr-eval JavaScript library, affecting over 800,000 weekly downloads and posing severe risks to dependent applications. The flaw arises from improper validation in the Parser.evaluate() function, al...

    Read More »
  • Critical vm2 sandbox flaw enables host code execution

    Critical vm2 sandbox flaw enables host code execution

    A critical sandbox escape vulnerability (CVE-2026-26956) has been discovered in the popular Node.js library vm2, allowing attackers to execute arbitrary code on the host system via WebAssembly exception handling that bypasses JavaScript-level protections. The flaw, confirmed in vm2 version 3.10.4...

    Read More »