Skip to content

Conversation

@GmailTedam
Copy link

Updates

  • Affected products

Comments
The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted variables object into the evaluate() function and trigger arbitrary code execution.

Copilot AI review requested due to automatic review settings November 9, 2025 19:20
@github-actions github-actions bot changed the base branch from main to GmailTedam/advisory-improvement-6404 November 9, 2025 19:21
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the modified timestamp in a GitHub security advisory JSON file for vulnerability GHSA-jc85-fpwf-qm7x (CVE-2025-12735), which affects the expr-eval npm package.

  • Updates the modification timestamp by 2 seconds to reflect the latest edit time

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@helixplant helixplant added the invalid This doesn't seem right label Nov 10, 2025
@helixplant helixplant closed this Nov 10, 2025
@github-actions github-actions bot deleted the GmailTedam-GHSA-jc85-fpwf-qm7x branch November 10, 2025 15:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

invalid This doesn't seem right

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants