Math.js: Unsafe object property setter in mathjs
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.6%
from disclosure to weapon13 days
Published on NVDApr 24
1st PoC+13d
exploitation probability
0.6%top 56% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
josdejong · mathjspublic PoCs found — 1
githubgithub.com/EQSTLab/CVE-2026-40897★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/security/cve/CVE-2026-40897https://bugzilla.redhat.com/show_bug.cgi?id=2461612https://github.com/josdejong/mathjs/commit/513ab2a0e01004af91b31aada68fae8a821326adhttps://github.com/josdejong/mathjs/pull/3656https://github.com/josdejong/mathjs/security/advisories/GHSA-29qv-4j9f-fjw5https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40897.json