GHSA-fm7p-gw32-828p: mathlive's Lack of Escaping of HTML allows for XSS
mediumvulnerability
security
Summary
MathLive, a math rendering library, has a vulnerability where the `\text{}` and `\mbox{}` commands don't properly escape HTML characters (like <, >, &, ") before inserting them into web pages, allowing XSS (cross-site scripting, where attackers inject malicious code that runs in users' browsers). This happens because the code sends raw, unescaped user input directly into the HTML markup and MathML output (a format for displaying mathematical notation).
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Patch Available
Yes
Disclosure Date
July 29, 2026
Classification
Attack SophisticationTrivial
Affected Packages
mathlive@<= 0.109.2 (fixed: 0.110.0)
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-fm7p-gw32-828p
First tracked: July 29, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%