Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41139

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

A flaw was found in math.js, an extensive math library for JavaScript and Node.js. This vulnerability allows an attacker to execute arbitrary JavaScript code by exploiting the expression parser. This could lead to a complete compromise of the system where math.js is used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4grafana-infinity-datasource-npmNot affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Enterprise Linux 10qt6-qtbaseNot affected
Red Hat Enterprise Linux 8qt5-qtbaseNot affected
Red Hat Enterprise Linux 9qt5-qtbaseNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-model-registry-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-monitoring-plugin-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2467648mathjs: math.js: Arbitrary code execution via expression parser

EPSS

Процентиль: 44%
0.00577
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

CVSS3: 8.8
github
4 месяца назад

mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes

EPSS

Процентиль: 44%
0.00577
Низкий

8.8 High

CVSS3