CVE-2026-40897

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*

History

30 Jun 2026, 03:19

Type Values Removed Values Added
CWE CWE-917
References
  • () https://access.redhat.com/security/cve/CVE-2026-40897 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2461612 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40897.json -

27 Apr 2026, 14:47

Type Values Removed Values Added
CPE cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*
First Time Mathjs
Mathjs mathjs
References () https://github.com/josdejong/mathjs/commit/513ab2a0e01004af91b31aada68fae8a821326ad - () https://github.com/josdejong/mathjs/commit/513ab2a0e01004af91b31aada68fae8a821326ad - Patch
References () https://github.com/josdejong/mathjs/pull/3656 - () https://github.com/josdejong/mathjs/pull/3656 - Issue Tracking
References () https://github.com/josdejong/mathjs/security/advisories/GHSA-29qv-4j9f-fjw5 - () https://github.com/josdejong/mathjs/security/advisories/GHSA-29qv-4j9f-fjw5 - Vendor Advisory

24 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 17:16

Updated : 2026-07-15 02:21


NVD link : CVE-2026-40897

Mitre link : CVE-2026-40897

CVE.ORG link : CVE-2026-40897


JSON object : View

Products Affected

mathjs

  • mathjs
CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')