8.8
/ 10
HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
AI Analysis
Arbitrary JavaScript can be executed via the expression parser of mathjs from version 13.1.0 to before version 15.2.0.
Basic Information
ID
CVE-2026-41139
Source
GitHub_M
Published
May 7, 2026 at 05:06
Affected Product
Vendor
josdejong
Product
mathjs
Version
>= 13.1.0, < 15.2.0
Affected Versions
josdejong mathjs >= 13.1.0, < 15.2.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
josdejong
Product
mathjs
Version
13.1.0-15.2.0
References
- github.com /josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g
- github.com /josdejong/mathjs/pull/3656
- github.com /josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4
- github.com /josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611
- github.com /josdejong/mathjs/releases/tag/v15.2.0