#VU125819 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs

 

#VU125819 Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs

Published: April 11, 2026


Vulnerability identifier: #VU125819
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mathjs
Software vendor:
Mathjs

Description

The vulnerability allows a remote user to execute arbitrary JavaScript.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the mathjs expression parser when evaluating arbitrary expressions. A remote user can submit a specially crafted expression to execute arbitrary JavaScript.

The issue affects applications that allow users to evaluate arbitrary expressions using the mathjs expression parser.


Remediation

Install security update from vendor's website.

External links