Executive brief
MathLive is a web component library used to display and edit mathematical formulas on websites. A security flaw allows attackers to embed malicious code within math expressions that, when rendered by the library, can execute arbitrary JavaScript in a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A cross-site scripting (XSS) vulnerability exists in MathLive due to improper output escaping of text-mode content within commands like \\text{} and \\mbox{}. The root cause is located in Box.toMarkup and the MathML serializer, where raw characters are concatenated into the final markup without being passed through an HTML/XML escaping function. This allows an attacker to provide LaTeX input containing malicious HTML tags (e.g., <img src=x onerror=alert(1)>) that are executed when the output is inserted into the DOM via sinks like innerHTML. The vulnerability affects several public APIs including convertLatexToMarkup, convertLatexToMathMl, and static elements like <math-span>. The issue is fixed in version 0.110.0 by implementing proper escaping for text-mode atoms.
Affected products
- arnog mathlive < 0.110.0
Timeline
- 2026-05-29: disclosed: Issue first reported to vendor
- 2026-06-08: patched: Fix committed to repository
- 2026-06-09: advisory: GitHub Security Advisory published
- 2026-07-29: advisory: NVD published CVE-2026-54705