string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
https://www.npmjs.com/package/string-math%2C
https://github.com/devrafalko/string-math/blob/master/string-math.js
https://gist.github.com/6en6ar/361608bccedb808061359481fe2f1b39