CVE-2026-41139

Source
https://cve.org/CVERecord?id=CVE-2026-41139
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41139.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41139
Aliases
Published
2026-05-07T05:06:28.746Z
Modified
2026-07-16T03:30:55.621054717Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Unsafe array index getter in mathjs
Details

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41139.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-915"
    ]
}
References

Affected packages

Git / github.com/josdejong/mathjs

Affected ranges

Type
GIT
Repo
https://github.com/josdejong/mathjs
Events
Database specific
{
    "cpe": "cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "13.1.0"
        },
        {
            "fixed": "15.2.0"
        }
    ]
}

Affected versions

v13.*
v13.1.0
v13.1.1
v13.2.0
v14.*
v14.0.0
v14.0.1
v14.1.0
v14.2.0
v14.2.1
v14.3.0
v14.3.1
v14.4.0
v15.*
v15.0.0
v15.1.0
v15.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41139.json"