CVE 8.8 HIGH

Math.js: Unsafe object property setter in mathjs_CVE-2026-40897

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

AI Analysis

Arbitrary JavaScript execution via mathjs expression parser

Basic Information

ID CVE-2026-40897
Source GitHub_M
Published Apr 24, 2026 at 16:48
Modified Apr 24, 2026 at 17:44

Affected Product

Vendor josdejong
Product mathjs
Version >= 13.1.1, < 15.2.0
Affected Versions josdejong mathjs >= 13.1.1, < 15.2.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor josdejong
Product mathjs
Version 13.1.1 to 15.2.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.