Report: CVE-2026-41139 - Unsafe array index getter in mathjs

Report: CVE-2026-41139 - Unsafe array index getter in mathjs

CVE ID :CVE-2026-41139 Published : May 7, 2026, 6:16 a.m. | 28 minutes ago Description :Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
May 7, 2026
Affected Product: Node.js