Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-12866: expr-eval could let attackers run unauthorized code

CVE-2026-12866 · published 5 days ago
Summary

The expr-eval library used in several JavaScript projects can be tricked into executing code that an attacker supplies. This could give a malicious user control over your application or server. Update to the latest patched versions of expr-eval, org.webjars.npm:expr-eval, and @rootio/expr-eval as soon as possible.

What to do
  • Update expr-eval to version 2.0.2-aikido.4.
  • Update rootio @rootio/expr-eval to version 2.0.2-root.io.4.
Affected software
Ecosystem VendorProductAffected versions
– – expr-eval < *
– – org.webjars.npm:expr-eval < *
npm – expr-eval <= 2.0.2
maven – org.webjars.npm:expr-eval <= 2.0.2
Root:npm – expr-eval < 2.0.2-aikido.4
Fix: upgrade to 2.0.2-aikido.4
Root:npm rootio @rootio/expr-eval < 2.0.2-root.io.4
Fix: upgrade to 2.0.2-root.io.4
Original advisory text
CVE-2026-12866 in expr-eval - Patched by Root
Root has patched CVE-2026-12866 in the expr-eval package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen23 Jun 2026
Track software like this
Free during beta