mathlive is vulnerable to Cross-Site Scripting (XSS)
63
Medium Risk
mathlive converts LaTeX into HTML and MathML for the editor, convertLatexToMarkup, and <math-span> / <math-div> static elements. The \text{} and \mbox{} commands accept arbitrary characters that were concatenated into markup without HTML escaping in both output paths. When applications render untrusted LaTeX and insert the result into the DOM, payloads such as embedded <img> tags with event handlers can execute arbitrary JavaScript. The fix escapes text-mode content and MathML text nodes so angle brackets and ampersands cannot break out of element content.
You are affected if you are using a version that falls within the vulnerable range.
mathlive is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 0.109.2.
Upgrade the mathlive library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant