Home

Description

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

PUBLISHED Reserved 2026-04-17 | Published 2026-05-07 | Updated 2026-05-07 | Assigner GitHub_M




HIGH: 8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes

Product status

>= 13.1.0, < 15.2.0
affected

References

github.com/...mathjs/security/advisories/GHSA-5v89-rwgr-qj6g

github.com/josdejong/mathjs/pull/3656

github.com/...ommit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4

github.com/...ommit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611

github.com/josdejong/mathjs/releases/tag/v15.2.0

cve.org (CVE-2026-41139)

nvd.nist.gov (CVE-2026-41139)

Download JSON