Moderate severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026
mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-54705
Description
MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and through convertLatexToMarkup, convertLatexToMathMl, , , and the default identity MathfieldElement.createHTML, allowing malicious input to run arbitrary JavaScript when rendered. This issue is fixed in version 0.110.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mathlivenpm | < 0.110.0 | 0.110.0 |
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-fm7p-gw32-828pghsaADVISORY
- github.com/arnog/mathlive/commit/5fe1c46153883f9ec0249a5c8c34e64aaae9cfb8ghsax_refsource_MISCWEB
- github.com/arnog/mathlive/issues/3028ghsax_refsource_MISCWEB
- github.com/arnog/mathlive/security/advisories/GHSA-fm7p-gw32-828pghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.