Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40897

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 8.8

Описание

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

A flaw was found in mathjs, an extensive math library for JavaScript and Node.js. This vulnerability allows a remote attacker to execute arbitrary JavaScript code by evaluating malicious expressions through the mathjs expression parser. This can lead to a complete compromise of the affected application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Enterprise Linux 10qt6-qtbaseNot affected
Red Hat Enterprise Linux 8qt5-qtbaseNot affected
Red Hat Enterprise Linux 9qt5-qtbaseNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-model-registry-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-monitoring-plugin-rhel9Not affected
Self-service automation portal 2ansible-automation-platform/automation-portalNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2461612mathjs: Math.js: Arbitrary code execution via expression parser

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. This vulnerability is fixed in 15.2.0.

CVSS3: 8.8
github
4 месяца назад

Unsafe object property setter in mathjs

8.8 High

CVSS3