216.73.217.22

CVE-2026-41139

· Published 07/05/2026 06:16 · Modified 07/05/2026 15:15

Labels: CVE-2026-41139 2026-05-07CVE-2026-41139CWE-915[email protected]

Essential information

Published
07/05/2026 06:16
Modified
07/05/2026 15:15
Author
Creator
CVSS
8.8 HIGH (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mathjs / math.js cpe:2.3:a:mathjs:math.js:13.1.0-15.2.0:*:*:*:*:*:*:*
mathjs / math.js cpe:2.3:a:mathjs:math.js:15.2.0:*:*:*:*:*:*:*

References