Topic: npm downloads
-
Critical RCE Flaw Found in Popular expr-eval JavaScript Library
A critical remote code execution vulnerability (CVE-2025-12735) has been found in the widely used expr-eval JavaScript library, affecting over 800,000 weekly downloads and posing severe risks to dependent applications. The flaw arises from improper validation in the Parser.evaluate() function, al...
Read More » -
Critical vm2 sandbox flaw enables host code execution
A critical sandbox escape vulnerability (CVE-2026-26956) has been discovered in the popular Node.js library vm2, allowing attackers to execute arbitrary code on the host system via WebAssembly exception handling that bypasses JavaScript-level protections. The flaw, confirmed in vm2 version 3.10.4...
Read More »