THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSS

[GHSA] GHSA-fm7p-gw32-828p (medium) — mathlive's Lack of Escaping of HTML allows for XSS

highgithub_advisoriesPublished 2026-07-29

GHSA-fm7p-gw32-828p Severity: medium CVE: CVE-2026-54705

mathlive's Lack of Escaping of HTML allows for XSS

### Summary

Despite the 0.104.0 patch escaping attribute-bearing constructs (`\htmlData`, `\href`), text-content reflection was missed. The `\text{}`, `\mbox{}` commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML outp

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fm7p-gw32-828p