Back to CVE List

CVE-2026-40897

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-915
Source
GitHub
Vendor
npm
Product
mathjs

External References

Discussion (0)

Add Comment

No comments yet. Be the first!