Junglewise Threat Intelligence

CVE-2018-1999024: MathJax XSS in unicode macro

CVE-2018-1999024 · Severity: low · CVSS 3 · Published 2018-07-27

Vendors: npm.

Executive brief

MathJax is a popular JavaScript library used to display mathematical notation in web browsers. A security flaw in how it handles certain mathematical macros allows an attacker to run unauthorized code in a user's browser if they view a page containing malicious content. This could lead to the theft of session information or unauthorized actions being performed on behalf of the user.

Technical details

A cross-site scripting (XSS) vulnerability exists in MathJax versions prior to 2.7.4. The flaw is located within the parsing and output logic of the \unicode{} macro (and related \class{} handling). An attacker can exploit this by providing a malicious TeX string that, when processed by MathJax on a webpage, executes arbitrary JavaScript in the context of the victim's browser session. This is a client-side attack requiring the victim to view a page where untrusted content is rendered via MathJax. The issue was addressed in version 2.7.4 by improving the sanitization and parsing of these macros.

Affected products

  • MathJax MathJax < 2.7.4

Timeline

  • 2018-06-01: other: External researcher blog post regarding exploit published
  • 2018-07-23: advisory: NVD published CVE-2018-1999024
  • 2018-07-27: advisory: GitHub Advisory GHSA-3c48-6pcv-88rm published
  • 2018-07-27: patched: Fix released in version 2.7.4

References

Related threats