CVE-2026-41139Disclosure(mathjs / mathjs)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mathjs

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
mathjs

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-09: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 105-0705-0805-0905-10
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
Full discourse4 posts
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-41139: mathjs RCE Flaw Exposes Apps to Code Injection https://thecybrdef.com/cve-2026-41139-mathjs-rce-code-injection-vulnerability/ #CVE202641139 hashtag#CyberNewsupdate hashtag#Cybersecurity

    Post summary

    A new RCE vulnerability in mathjs (CVE-2026-41139) has been disclosed, indicating code injection potential; no PoC, exploit, patch, or active exploitation claims are provided.

    0000044
    9 followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-41139: mathjs RCE Flaw Exposes Apps to Code Injection https://thecybrdef.com/cve-2026-41139-mathjs-rce-code-injection-vulnerability/ #CVE202641139 hashtag#CyberNewsupdate hashtag#Cybersecurity

    Post summary

    The text announces the discovery of an RCE vulnerability in mathjs that allows code injection, providing a link for further details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000032
    2 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-41139: mathjs RCE Flaw Exposes Apps to Code Injection https://thecybrdef.com/cve-2026-41139-mathjs-rce-code-injection-vulnerability/ #CVE202641139 hashtag#CyberNewsupdate hashtag#Cybersecurity

    Post summary

    The post announces the MathJS RCE vulnerability (CVE-2026-41139) and describes it as a code injection flaw, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000046
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41139 Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression… https://www.cve.org/CVERecord?id=CVE-2026-41139

    Post summary

    The post announces CVE-2026-41139, describing an arbitrary JavaScript execution flaw in Math.js from versions 13.1.0 through 15.2.0.

    0000081
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmathjsmathjs-node.js-

Explore more