Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs - #VU125819

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs - #VU125819

Published: April 11, 2026


Vulnerability identifier: #VU125819
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Mathjs
Affected software:
Mathjs

Detailed vulnerability description

The vulnerability allows a remote user to execute arbitrary JavaScript.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the mathjs expression parser when evaluating arbitrary expressions. A remote user can submit a specially crafted expression to execute arbitrary JavaScript.

The issue affects applications that allow users to evaluate arbitrary expressions using the mathjs expression parser.


Remediation

Install security update from vendor's website.

Sources