Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
References
| Link | Resource |
|---|---|
| https://github.com/josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4 | Patch |
| https://github.com/josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611 | Patch |
| https://github.com/josdejong/mathjs/pull/3656 | Issue Tracking Patch |
| https://github.com/josdejong/mathjs/releases/tag/v15.2.0 | Release Notes |
| https://github.com/josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g | Patch Vendor Advisory |
Configurations
History
08 May 2026, 17:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4 - Patch | |
| References | () https://github.com/josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611 - Patch | |
| References | () https://github.com/josdejong/mathjs/pull/3656 - Issue Tracking, Patch | |
| References | () https://github.com/josdejong/mathjs/releases/tag/v15.2.0 - Release Notes | |
| References | () https://github.com/josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:* | |
| First Time |
Mathjs mathjs
Mathjs |
07 May 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 06:16
Updated : 2026-05-08 17:06
NVD link : CVE-2026-41139
Mitre link : CVE-2026-41139
CVE.ORG link : CVE-2026-41139
JSON object : View
Products Affected
mathjs
- mathjs
CWE
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
