maven package report

Is org.webjars.npm:expr-eval safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.2
high

severity out of 10

epss
0.87%
medium

chance of exploitation in 30 days, 57th percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-q9v2-7m5w-4693, the advisory selected below

// 1 advisories

GHSA-q9v2-7m5w-4693

CRITICALCVE-2026-12866

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected
<= 2.0.2
Fixed in
not stated
Weakness
CWE-94, Code injection
Published
2026-06-23, updated 2026-09-22
Sources
github
// references

// dependencies

0 direct

Create a free accountfor dependency paths and remediation
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 17:30 UTC. The most recent advisory here was published 2026-06-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.webjars.npm:expr-eval safe? maven package security report | CyberXYZ