Skip to content

chore: Update expr-eval@2.0.2 to 3.0.1 [SECURITY]#999

Open
everettbu wants to merge 1 commit into
masterfrom
renovate/npm-expr-eval2.0.2-vulnerability
Open

chore: Update expr-eval@2.0.2 to 3.0.1 [SECURITY]#999
everettbu wants to merge 1 commit into
masterfrom
renovate/npm-expr-eval2.0.2-vulnerability

Conversation

@everettbu

@everettbu everettbu commented Jan 25, 2026

Copy link
Copy Markdown

Mirror of n8n-io/n8n#24833
Original author: app/renovate


This PR contains the following updates:

Package Change Age Confidence
expr-eval@2.0.2 3.0.03.0.1 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


expr-eval does not restrict functions passed to the evaluate function

CVE-2025-12735 / GHSA-jc85-fpwf-qm7x

More information

Details

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted variables object into the evaluate() function and trigger arbitrary code execution.

Severity

  • CVSS Score: Unknown
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

jorenbroekema/expr-eval (expr-eval`@2`.0.2)

v3.0.1

Compare Source

Added

Configuration

📅 Schedule: Branch creation - "" in timezone UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@everettbu everettbu added community Authored by a community member in linear Issue or PR has been created in Linear for internal review security vulnerability labels Jan 25, 2026
@everettbu
everettbu force-pushed the renovate/npm-expr-eval2.0.2-vulnerability branch from bce1a2f to 929e862 Compare February 8, 2026 08:35
@everettbu
everettbu force-pushed the renovate/npm-expr-eval2.0.2-vulnerability branch from 929e862 to ae307f3 Compare February 15, 2026 11:54
@everettbu
everettbu force-pushed the renovate/npm-expr-eval2.0.2-vulnerability branch from ae307f3 to 318762a Compare February 23, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community Authored by a community member in linear Issue or PR has been created in Linear for internal review security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant