CVE-2026-40897: Arbitrary JavaScript Execution in Math.js Expression Parser
CVE-2026-40897 reveals a CVSS 8.8 HIGH flaw in Math.js that lets authenticated attackers execute arbitrary JavaScript server-side through the expression parser. Upgrade to 15.2.0 now.
Team Nippysoft