expr-eval: expr-eval: Code Execution via crafted expressions in toJSFunction() API
Published Jun 23, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.87%
Description
All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.
Affected products
- Vendor n/a Product Expr-Eval Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
- Vendor n/a Product Org.webjars.npm:expr-Eval Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Expr-Eval | n/a |
| ||||||
| n/a | Org.webjars.npm:expr-Eval | n/a |
|
No data.
No data.
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
org.webjars.npm:expr-eval
Maven
Introduced 0 Fixed not fixedexpr-eval
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Maven | org.webjars.npm:expr-eval | 0 | not fixed |
| npm | expr-eval | 0 | not fixed |
Remediation
Red Hat statement
RHEL AI 3.4 bootc images ship expr-eval@2.0.2 as a dependency of @langchain/community. The only identified consumer is the LangChain Calculator tool, which calls Parser.evaluate() and does not invoke toJSFunction(). CVE-2026-12866 affects only the toJSFunction() API. No other npm package in the image depends on expr-eval. For this reason the issue is rated Low for RHEL AI.
Red Hat mitigation
LangChainJS already replaced expr-eval with math-expression-evaluator in a later @langchain/community release (fix for CVE-2025-12735). Bootc owners should bump @langchain/community to a version that no longer bundles expr-eval, which removes the dead dependency entirely.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jun 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.87% (0.00866) | 57.19th | v5 (v2026.06.15) |
| Jun 23, 2026 | 0.45% (0.00454) | 36.00th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-12866 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491633 Issue Tracking
- https://github.com/advisories/GHSA-q9v2-7m5w-4693 Advisory
- https://github.com/silentmatt/expr-eval/blob/master/src/expression.js#L55
- https://github.com/silentmatt/expr-eval/blob/master/src/expression.js%23L55
- https://github.com/silentmatt/expr-eval/issues/292
- https://nvd.nist.gov/vuln/detail/CVE-2026-12866
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-17662018
- https://security.snyk.io/vuln/SNYK-JS-EXPREVAL-15054690 exploit
- https://www.cve.org/CVERecord?id=CVE-2026-12866
Change history (0)
No recorded changes yet.