Junglewise Threat Intelligence

CVE-2026-54705: Arno Gourdol MathLive XSS in text-mode rendering

CVE-2026-54705 · Severity: medium · CVSS 6.3 · Published 2026-07-29

Technologies: mathlive (npm). Vendors: npm.

Executive brief

MathLive is a web component library used to display and edit mathematical formulas on websites. A security flaw allows attackers to embed malicious code within math expressions that, when rendered by the library, can execute arbitrary JavaScript in a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in MathLive due to improper output escaping of text-mode content within commands like \\text{} and \\mbox{}. The root cause is located in Box.toMarkup and the MathML serializer, where raw characters are concatenated into the final markup without being passed through an HTML/XML escaping function. This allows an attacker to provide LaTeX input containing malicious HTML tags (e.g., <img src=x onerror=alert(1)>) that are executed when the output is inserted into the DOM via sinks like innerHTML. The vulnerability affects several public APIs including convertLatexToMarkup, convertLatexToMathMl, and static elements like <math-span>. The issue is fixed in version 0.110.0 by implementing proper escaping for text-mode atoms.

Affected products

  • arnog mathlive < 0.110.0

Timeline

  • 2026-05-29: disclosed: Issue first reported to vendor
  • 2026-06-08: patched: Fix committed to repository
  • 2026-06-09: advisory: GitHub Security Advisory published
  • 2026-07-29: advisory: NVD published CVE-2026-54705

References

Related threats