CVE-2026-40897 is an arbitrary code execution vulnerability in Math.js, an extensive math library for JavaScript and Node.js. The issue affects Math.js versions 13.1.1 through versions prior to 15.2.0. According to the provided content, the flaw allows execution of arbitrary JavaScript via the mathjs expression parser when an application permits users to evaluate arbitrary expressions, including through APIs such as math.evaluate(). In server-side Node.js deployments, exploitation can result in unauthenticated remote code execution in the context of the running application process. In browser-based deployments, the same parser exposure can enable client-side script execution and manipulation of browser objects such as window and document. The issue was fixed in Math.js 15.2.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This three-file repository is a self-contained vulnerable-environment and proof-of-concept repository for claimed CVE-2026-40897. Dockerfile builds a Node.js 20.18.0 image, installs mathjs@15.1.0, copies server.js, and writes a demonstration flag to /flag.txt. server.js creates an HTTP calculator on port 3000; its POST /calculate route directly evaluates untrusted expr input through Math.js. The embedded browser UI sends calculator input to that route. README documents a Math.js expression-parser sandbox bypass: it leaks ArrayNode internals via toJSON(), overwrites an internal map path, reaches Function.constructor through FunctionAssignmentNode serialization, and executes attacker-provided JavaScript. The supplied payload uses child_process.execSync to launch a Bash reverse shell to ATTACKER_IP:4444. No exploit framework is used; the JavaScript server is the runnable target application, while the exploit payload is documented in README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary JavaScript execution vulnerability in the mathjs expression parser affecting Math.js versions 13.1.1 through before 15.2.0.
A vulnerability affecting applications that use math.evaluate() on user-supplied expressions, leading to unauthenticated remote code execution in server-side Node.js deployments and XSS/client-side context manipulation in browser environments.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.