Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-12866: expr-eval could let attackers run unauthorized code
CVE-2026-12866 · published 5 days ago
Summary
The expr-eval library used in several JavaScript projects can be tricked into executing code that an attacker supplies. This could give a malicious user control over your application or server. Update to the latest patched versions of expr-eval, org.webjars.npm:expr-eval, and @rootio/expr-eval as soon as possible.
What to do
- Update expr-eval to version 2.0.2-aikido.4.
- Update rootio @rootio/expr-eval to version 2.0.2-root.io.4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | – | expr-eval | < * |
| – | – | org.webjars.npm:expr-eval | < * |
| npm | – | expr-eval | <= 2.0.2 |
| maven | – | org.webjars.npm:expr-eval | <= 2.0.2 |
| Root:npm | – | expr-eval |
< 2.0.2-aikido.4 Fix: upgrade to 2.0.2-aikido.4
|
| Root:npm | rootio | @rootio/expr-eval |
< 2.0.2-root.io.4 Fix: upgrade to 2.0.2-root.io.4
|
Original advisory text
CVE-2026-12866 in expr-eval - Patched by Root
Root has patched CVE-2026-12866 in the expr-eval package for Root:npm. Multiple fixed versions available.
References
- https://github.com/silentmatt/expr-eval/blob/master/src/expression.js%23L55
- https://nvd.nist.gov/vuln/detail/CVE-2026-12866
- https://github.com/silentmatt/expr-eval/blob/master/src/expression.js#L55
- https://github.com/advisories/GHSA-q9v2-7m5w-4693
- https://github.com/silentmatt/expr-eval Product
- https://github.com/silentmatt/expr-eval/issues/292
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-17662018
- https://security.snyk.io/vuln/SNYK-JS-EXPREVAL-15054690
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-94Code Injection
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen23 Jun 2026
Sources
CVE-2026-12866 · NVD
CVE-2026-12866 · MITRE
GHSA-q9v2-7m5w-4693 · GHSA
GHSA-q9v2-7m5w-4693 · OSV
Track software like this
Free during beta