CVE-2026-41139

high
Published 2026-05-07 · Modified 2026-05-08
CVSS v3
8.8
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/josdejong/mathjs/security/advisories/GHSA-5v89-rwgr-qj6g

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/josdejong/mathjs/releases/tag/v15.2.0

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/josdejong/mathjs/pull/3656

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/josdejong/mathjs/commit/bcf0da46f0b8577ec03c9ecd7bff8b5c2543a611

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/josdejong/mathjs/commit/0aee2f61866e35ffa0aef915221cdf6b026ffdd4

Package impact

EcosystemPackageVulnerableFixed
npm npmmathjs>=13.1.0,<15.2.015.2.0
npm NPMmathjs>= 13.1.0, < 15.2.015.2.0

Application impact

VendorProductVersionsFixed
mathjsmathjs{"startIncluding":"13.1.0","endExcluding":"15.2.0"}15.2.0

References

CWEs

CWE-915

Verify integrity in audit chain (admin only). AS-IS.