CVE-2026-41139

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*

History

08 May 2026, 17:06

Type Values Removed Values Added
References () https://github.com/josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4 - () https://github.com/josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4 - Patch
References () https://github.com/josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611 - () https://github.com/josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611 - Patch
References () https://github.com/josdejong/mathjs/pull/3656 - () https://github.com/josdejong/mathjs/pull/3656 - Issue Tracking, Patch
References () https://github.com/josdejong/mathjs/releases/tag/v15.2.0 - () https://github.com/josdejong/mathjs/releases/tag/v15.2.0 - Release Notes
References () https://github.com/josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g - () https://github.com/josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g - Patch, Vendor Advisory
CPE cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*
First Time Mathjs mathjs
Mathjs

07 May 2026, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 06:16

Updated : 2026-05-08 17:06


NVD link : CVE-2026-41139

Mitre link : CVE-2026-41139

CVE.ORG link : CVE-2026-41139


JSON object : View

Products Affected

mathjs

  • mathjs
CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes