Vulnerabilities/

MathLive's Lack of Escaping of HTML allows for XSS

Severity:
Medium

Description

Despite normal text rendering as LaTeX expressions, preventing XSS, the library also provides users with commands which may modify HTML, such as the \htmlData command, and the lack of escaping leads to XSS.

Recommendation

Update the mathlive package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mathlive
Anything's wrong? Let us know Last updated on April 02, 2025

This issue is available in SmartScanner Professional

See Pricing