Description
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
Problem types
CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
Product status
References
github.com/...mathjs/security/advisories/GHSA-5v89-rwgr-qj6g
github.com/josdejong/mathjs/pull/3656
github.com/...ommit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4
github.com/...ommit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611
github.com/josdejong/mathjs/releases/tag/v15.2.0