THREAT OPS › Threat News › [GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSS
[GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSS
GHSA-fm7p-gw32-828p Severity: medium CVE: CVE-2026-54705
mathlive's Lack of Escaping of HTML allows for XSS
### Summary
Despite the 0.104.0 patch escaping attribute-bearing constructs (`\htmlData`, `\href`), text-content reflection was missed. The `\text{}`, `\mbox{}` commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML outp
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-54705cve
- https://mathlive.io/mathfield/demo/url
Original source: https://github.com/advisories/GHSA-fm7p-gw32-828p