Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs - #VU125819

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Mathjs - #VU125819

Published: April 11, 2026


Vulnerability identifier: #VU125819
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the mathjs expression parser when evaluating arbitrary expressions. A remote user can submit a specially crafted expression to execute arbitrary JavaScript.

The issue affects applications that allow users to evaluate arbitrary expressions using the mathjs expression parser.


Affected software

Mathjs

Remediation

Install security update from vendor's website.

Mathjs - update to 15.2.0

External References

Related Security Bulletins