CVE-2026-12866 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-12866 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-12866 is a critical remote code execution flaw in expr-eval affecting all versions of the package. The vulnerable toJSFunction() API turns user-supplied expressions into executable JavaScript using new Function(), which can let an attacker break out of the expression sandbox and run arbitrary code in your application’s context. For solo developers and small teams, this is especially dangerous because a single exposed endpoint, webhook, admin tool, or “formula” feature may be enough to compromise the whole app.
KEV status: No. Exploited in the wild: No. Even without known active exploitation, this should be treated as an urgent patch-and-audit issue because the impact is full code execution.
Immediate Action
- Stop using
toJSFunction()on any input that can be influenced by users, customers, tenants, or external systems. - Upgrade or replace
expr-evalimmediately. If a fixed version is not yet published, remove the dependency or disable the feature until a safe release is available. See the vendor advisory: TODO: vendor advisory link. - Rollback to a release that does not expose expression compilation if you cannot patch within minutes. Prefer disabling the feature over leaving it exposed.
- Isolate the service: run it with minimal filesystem and network permissions, no cloud metadata access, and no long-lived secrets in environment variables.
- Rotate secrets if the vulnerable path was reachable in production: API keys, database passwords, signing keys, and session secrets.
- Audit logs for requests containing unusual expressions, long payloads, or strings that look like JavaScript operators, function bodies, or template-like code.
Affected Versions
expr-eval@all versionsvulnerable viatoJSFunction()expr-eval@<= TODO_SAFE_VERSIONvulnerable; upgrade toTODO_SAFE_VERSIONor laterexpr-eval@latestshould be verified before deployment; do not assume it is fixed until confirmed in release notes
Resolution Guide
JavaScript / Node.js
# npm
npm uninstall expr-eval
npm install expr-eval@TODO_SAFE_VERSION
# yarn
yarn remove expr-eval
yarn add expr-eval@TODO_SAFE_VERSION
# pnpm
pnpm remove expr-eval
pnpm add expr-eval@TODO_SAFE_VERSION
Python (if bundled in tooling, scripts, or wrappers)
# pip
pip uninstall expr-eval
# pipx
pipx uninstall expr-eval
Java (if repackaged in a service or embedded via a wrapper)
# Maven
mvn dependency:tree | grep -i expr-eval
# Gradle
./gradlew dependencies --configuration runtimeClasspath | grep -i expr-eval
Linux package managers (only if your distro or internal package mirrors ship it)
# apt
sudo apt remove expr-eval
# yum/dnf
sudo yum remove expr-eval
sudo dnf remove expr-eval
Docker
# Rebuild with a patched dependency and a fresh image tag
docker build --no-cache -t yourapp:patched .
docker run --rm yourapp:patched
Hardening examples
// Disable expression compilation entirely
const allowCompiledExpressions = false;
if (!allowCompiledExpressions) {
throw new Error("Expression compilation disabled for security");
}
// Prefer a safe allowlist approach
const allowedFields = new Set(["price", "qty", "tax"]);
function validateExpression(expr) {
// Reject if it contains unsupported tokens or function-like syntax
if (/[{};]|function|=>|new\s+Function/i.test(expr)) {
throw new Error("Unsafe expression");
}
}
Minimal code fix pattern
// Before: unsafe if expr is user-controlled
const fn = parser.parse(userExpression).toJSFunction(["x", "y"]);
// After: avoid compiling to JS; evaluate only trusted, pre-approved expressions
validateExpression(userExpression);
const ast = parser.parse(userExpression);
const result = ast.evaluate({ x: 1, y: 2 });
Detection & Verification
Check whether you are vulnerable:
# Find installed version in Node projects
npm ls expr-eval
yarn why expr-eval
pnpm why expr-eval
# Search code for the dangerous API
grep -RIn "toJSFunction(" .
grep -RIn "expr-eval" .
Dependency audit:
npm audit
yarn audit
pnpm audit
Verify the fix:
# Confirm the vulnerable package is gone or upgraded
npm ls expr-eval
# Confirm no code paths still call the dangerous API
grep -RIn "toJSFunction(" src test .
# Run a quick smoke test on the feature after patching
node -e "const { Parser } = require('expr-eval'); console.log('loaded');"
Operational verification: ensure the service no longer accepts arbitrary expression bodies from untrusted users, and confirm the feature is disabled or constrained to a strict allowlist. If you use CI, add a dependency check that fails builds when expr-eval is present below TODO_SAFE_VERSION.
Risk and Impact
If exploited, an attacker can execute arbitrary JavaScript inside your app, which may lead to data theft, secret exfiltration, account takeover, lateral movement, or full server compromise. In small-team environments, the blast radius is often larger than expected because the same service may hold production credentials, deployment tokens, and access to internal APIs. Treat any reachable use of toJSFunction() as a high-priority incident until removed or fully isolated.