Vulnerabilities/

mathlive's Lack of Escaping of HTML allows for XSS - mathlive

Severity:
Medium

Description

Despite the 0.104.0 patch escaping attribute-bearing constructs (\htmlData, \href), text-content reflection was missed. The \text{}, \mbox{} commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML output, leading to XSS.

Recommendation

Update the mathlive package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mathlive
Anything's wrong? Let us know Last updated on July 29, 2026