CVE-2026-41507 — math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. Thi — CVE Database · The Intelligence Room