Description
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
Remediation
References
Related Vulnerabilities
WordPress Plugin Meta Slider and Carousel with Lightbox Cross-Site Request Forgery (1.6.2)
MySQL CVE-2021-35612 Vulnerability (CVE-2021-35612)
Hiawatha CVE-2025-57783 Vulnerability (CVE-2025-57783)
MySQL CVE-2022-21600 Vulnerability (CVE-2022-21600)
PHP-Fusion Improper Privilege Management Vulnerability (CVE-2020-24949)