Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40897

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mathjs:mathjs:*:*:*:*:*:node.js:*:*
Версия от 13.1.1 (включая) до 15.2.0 (исключая)

EPSS

Процентиль: 43%
0.00551
Низкий

8.8 High

CVSS3

Дефекты

CWE-915
CWE-917

Связанные уязвимости

CVSS3: 8.8
redhat
3 месяца назад

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

CVSS3: 8.8
github
4 месяца назад

Unsafe object property setter in mathjs

EPSS

Процентиль: 43%
0.00551
Низкий

8.8 High

CVSS3

Дефекты

CWE-915
CWE-917