highCVSS 8.8Vulnerability

GHSA-jvff-x2qm-6286

### Impact Two security vulnerabilities, the first of which was introduced in version 13.1.0, were detected that allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser. ### Patches The problem is patched in mathjs v15.2.0. ### Workarounds There is no workaround without upgrading.

Properties

ghsa_id
GHSA-jvff-x2qm-6286
severity
high
summary
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
cvss_score
8.8
cve_id
GHSA-jvff-x2qm-6286
cvss_vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-04-10T22:10:49Z
source_url
https://github.com/advisories/GHSA-jvff-x2qm-6286
ghsa_updated
2026-04-14T15:10:36Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/mathjs

AFFECTS (1)

[Software]npm/mathjs

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Dynamically-Determined Object Attributes

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-jvff-x2qm-6286 (CVSS 8.8) — Ninja Signal Threat Intelligence | Ninja Signal