CVE-2026-40897

Source
https://cve.org/CVERecord?id=CVE-2026-40897
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40897.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40897
Aliases
Related
Published
2026-04-24T16:48:34.849Z
Modified
2026-08-12T03:51:23.368867497Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Math.js: Unsafe object property setter in mathjs
Details

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

Database specific
{
    "cwe_ids": [
        "CWE-915"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40897.json"
}
References

Affected packages

Git / github.com/josdejong/mathjs

Affected ranges

Type
GIT
Repo
https://github.com/josdejong/mathjs
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "13.1.1"
        },
        {
            "fixed": "15.2.0"
        }
    ]
}

Affected versions

v13.*
v13.1.1
v13.2.0
v14.*
v14.0.0
v14.0.1
v14.1.0
v14.2.0
v14.2.1
v14.3.0
v14.3.1
v14.4.0
v15.*
v15.0.0
v15.1.0
v15.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40897.json"