CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54705

CVE-2026-54705: DOM-Based Cross-Site Scripting in MathLive LaTeX Rendering Engine

Amit Schendel
Amit Schendel
Senior Security Researcher

Jul 29, 2026·7 min read·55 visits

Executive Summary (TL;DR)

MathLive versions < 0.110.0 fail to escape text-mode commands (like \text{} and \mbox{}), enabling DOM-based Cross-Site Scripting (XSS) when rendering untrusted LaTeX.

CVE-2026-54705 is a critical DOM-based Cross-Site Scripting (XSS) vulnerability affecting the MathLive library prior to version 0.110.0. The flaw stems from a lack of proper character escaping in the rendering path for LaTeX text-mode commands such as \text{} and \mbox{}, enabling unauthenticated attackers to execute arbitrary JavaScript in the victim's browser.

Vulnerability Overview

MathLive is a widely used web component library designed to display and input mathematical formulas in web applications. The library is frequently integrated into interactive systems such as learning management systems (LMS), online assessment platforms, and scientific calculators. The attack surface centers on its parsing of LaTeX strings to construct dynamic HTML and MathML representations within the browser.\n\nThis analysis centers on a DOM-based Cross-Site Scripting (XSS) vulnerability registered as CVE-2026-54705 (and GHSA-fm7p-gw32-828p). The vulnerability exists within MathLive versions prior to 0.110.0, where LaTeX text-mode commands—specifically \text{} and \mbox{}—fail to undergo proper character escaping when mapped to HTML and MathML elements. Consequently, if an application renders mathematical expressions derived from user-supplied inputs, arbitrary markup and script tags can inject directly into the DOM.\n\nThe weakness is classified under CWE-116: Improper Encoding or Escaping of Output. The impact allows a malicious actor to achieve client-side code execution in the context of the user's browser session. Because MathLive is used within static custom components, such as <math-span> and <math-div>, the vulnerable code paths are exposed whenever these elements receive raw user content.

Root Cause Analysis

The underlying technical flaw rests in the serialization stage where raw text representations within text-mode LaTeX tags are converted into HTML markup and MathML structures. During parsing, MathLive maps command content to specialized structural objects. When encountering text-mode commands like \text{} or \mbox{}, the parser creates a TextAtom. The raw content of this atom is stored directly inside its value property.\n\nDuring rendering, the HTML generator in src/core/box.ts calls Box.toMarkup to serialize internal box structures into string representations. Prior to version 0.110.0, this method took the literal value of the TextAtom and concatenated it directly with adjacent HTML nodes without performing sanitization or character encoding. Consequently, metacharacters such as <, >, and & remained unmodified in the output stream.\n\nIn tandem, the MathML output generator in src/formats/atom-to-math-ml.ts suffered from a parallel vulnerability. The helper function xmlEscape was designed to sanitize output; however, the replacement rule for the ampersand character (&) was commented out. Additionally, text processing handlers like scanText and the case handler for mode === 'text' wrote the atom.value directly into <mtext> elements without executing any XML escape routines. This omission enabled direct tag injection into the generated MathML nodes.\n\nThe final link in the execution chain involves how these strings are loaded into the browser document. Static custom elements like <math-span> rely directly on utility pipelines that read the raw content and dump the compiled HTML or MathML string directly into dynamic sinks such as innerHTML. In standard configurations, the default output filter MathfieldElement.createHTML did not enforce sanitization, transforming standard user-supplied text nodes into unhindered scripting contexts.

Code-Level Patch Analysis

To fully understand the mechanics of the vulnerability and the subsequent remediation, we can compare the vulnerable code pathways with the patch introduced in commit 5fe1c46153883f9ec0249a5c8c34e64aaae9cfb8.\n\nIn src/core/box.ts, the original implementation of Box.toMarkup handled the body text directly from this.value with no escaping wrapper:\n\ntypescript\n// VULNERABLE CODE (src/core/box.ts)\ntoMarkup(): string {\n let body = this.value ?? '';\n // ... body is concatenated to HTML without escaping\n}\n\n\nThe patch introduces an escapeText helper that sanitizes ampersands and angle brackets before string injection, ensuring that standard text-mode nodes are rendered safely between tags:\n\ntypescript\n// PATCHED CODE (src/core/box.ts)\ntoMarkup(): string {\n let body = this.value ? escapeText(this.value) : '';\n // ...\n}\n\nfunction escapeText(s: string): string {\n return s\n .replace(/&/g, '&amp;')\n .replace(/</g, '&lt;')\n .replace(/>/g, '&gt;');\n}\n\n\nWithin the MathML serializer at src/formats/atom-to-math-ml.ts, the critical XML escape function had its ampersand replacement rule disabled, allowing structural character bypasses. The patch restored this rule first to avoid double-escaping downstream entities:\n\ntypescript\n// VULNERABLE VS PATCHED (src/formats/atom-to-math-ml.ts)\nfunction xmlEscape(string: string): string {\n return (\n string\n // .replace(/&/g, '&amp;') <--- COMMENTED OUT IN VULNERABLE VERSION\n .replace(/&/g, '&amp;') // <--- RESTORED IN PATCH\n .replace(/"/g, '&quot;')\n // ...\n );\n}\n\n\nAdditionally, multiple case structures in atomToMathML that directly interpolated atom.value or specialized delimiters were updated to route values through xmlEscape:\n\ntypescript\n// PATCHED CASE FOR TEXT-MODE ATOMS\ncase 'text':\n result += `<mtext ${makeID(atom.id, options)}x>${xmlEscape(atom.value)}</mtext>`;\n break;\n\n\nThis remediation strategy is structurally complete. It intercepts text elements at the conversion layer rather than trusting callers to sanitize the final product. By updating both HTML and MathML serializers, MathLive ensures that regardless of the chosen render path, metacharacters remain neutralized.

Exploitation and Proof-of-Concept Analysis

Exploitation of CVE-2026-54705 is highly reliable and requires no authentication if the target application displays math content to unauthenticated users. The attack relies on an attacker embedding malicious HTML directly into LaTeX commands that support raw text representations. When a victim loads the compromised page, the browser evaluates the payload.\n\nConsider a user-facing mathematical forum or assignment system that allows students to submit math equations in LaTeX format. An attacker inputs a standard payload wrapped in a \\text{} block:\n\nlatex\n\\text{<img src=x onerror=alert(document.domain)>}\n\n\nThe following diagram visualizes the structural flow of the attack vector:\n\nmermaid\ngraph LR\n A["Malicious LaTeX Input"] -->|\\text{...}| B["MathLive Engine"]\n B -->|Box.toMarkup / atomToMathML| C["Unescaped HTML/MathML String"]\n C -->|Static Custom Element render / innerHTML| D["Browser DOM Sink"]\n D -->|Parsing & Execution| E["Arbitrary JavaScript Execution"]\n\n\nWhen the system attempts to render the expression using the static custom elements or standard compiler hooks, it outputs raw HTML tags directly. The browser parses the <img src=x onerror=...> block as actual HTML markup. Because the source attribute is intentionally invalid (x), the onerror handler triggers immediately in the context of the user's active session, executing the payload.

Security Impact and Threat Intelligence

The security impact of CVE-2026-54705 is severe for web applications processing untrusted user content. In a DOM-based Cross-Site Scripting vulnerability, the attacker gains full control over the client-side execution environment. Under the security context of the affected domain, the attacker can hijack active sessions, steal authentication tokens, or modify the user interface dynamically.\n\nIn learning environments, this flaw could allow students to manipulate grading records, leak assessment answers, or hijack teacher sessions. If the host application uses cookies without the HttpOnly flag or stores sensitive keys in LocalStorage, an attacker can exfiltrate this data silently to an external logging server. Furthermore, the vulnerability can serve as a pivot for broader client-side attacks, including credential harvesting via mock login forms.\n\nThe CVSS v3.1 base score is calculated at 6.3 (Medium), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L. While classified as Medium, applications that integrate MathLive into high-privilege context areas (such as admin panels or configuration pages) effectively escalate the real-world impact to Critical. Currently, VulnCheck classifies the exploit status as Proof-of-Concept, and it is not yet listed on the CISA KEV catalog.

Remediation and Defensive Countermeasures

Remediation requires upgrading the mathlive NPM package to version 0.110.0 or higher. This release contains the formal patch which incorporates the HTML/XML escaping filters. To update, developers should run the standard dependency update commands matching their chosen package manager.\n\nbash\nnpm install mathlive@0.110.0\n# or for yarn\nyarn add mathlive@0.110.0\n\n\nIf upgrading is not immediately feasible, developers must insert a sanitization layer between MathLive's conversion functions and the DOM. The library DOMPurify should be used to scrub the output of convertLatexToMarkup before assignment to an element's innerHTML property:\n\njavascript\nimport DOMPurify from 'dompurify';\nimport { convertLatexToMarkup } from 'mathlive';\n\nconst rawOutput = convertLatexToMarkup(untrustedLaTeX);\nconst safeOutput = DOMPurify.sanitize(rawOutput);\ncontainer.innerHTML = safeOutput;\n\n\nAdditionally, enforcing a strict Content Security Policy (CSP) provides a robust defense-in-depth barrier. Restricting script execution by disallowing 'unsafe-inline' prevents injected event handlers (such as onerror) from executing even if the escaping logic fails.

Official Patches

arnogGitHub Security Advisory GHSA-fm7p-gw32-828p

Fix Analysis (1)

Technical Appendix

CVSS Score
6.3/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Systems

mathlive NPM library

Affected Versions Detail

Product
Affected Versions
Fixed Version
mathlive
arnog
< 0.110.00.110.0
AttributeDetail
CWE IDCWE-116
Attack VectorNetwork (AV:N)
CVSS v3.1 Score6.3
Exploit StatusPoC Available
CISA KEV StatusNot Listed
ImpactDOM-based Cross-Site Scripting (XSS)

MITRE ATT&CK Mapping

T1189Drive-by Compromise
Initial Access
T1204.002User Execution: Malicious Link
Execution
CWE-116
Improper Encoding or Escaping of Output

The software does not escape or encodes output correctly, allowing attackers to inject raw markup.

Known Exploits & Detection

GitHub Issue #3028Original bug report demonstrating XSS via static math components.

Vulnerability Timeline

Vulnerability reported to MathLive project by CosmicCrusader23
2026-05-29
Security fix committed to main branch by Arno Gourdol
2026-06-09
GitHub Advisory GHSA-fm7p-gw32-828p published
2026-07-29
CVE-2026-54705 assigned and published
2026-07-29

References & Sources

  • [1]GitHub Security Advisory
  • [2]MathLive Issue #3028
  • [3]MathLive Fix Commit

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 6 hours ago•CVE-2026-107844
5.3

CVE-2026-107844: Path Traversal Vulnerability in Contao ImagesController

A path traversal vulnerability (CWE-22) in Contao CMS allows unauthenticated remote attackers to bypass directory boundary restrictions in ImagesController and access files within the project directory.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 8 hours ago•CVE-2026-107848
3.5

CVE-2026-107848: Cross-Site Request Forgery (CSRF) in Contao Backend Actions via GET Requests

Contao Open Source CMS versions 4.0.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 contain a Cross-Site Request Forgery (CSRF) vulnerability in backend parameter handling. The `RequestTokenListener` component validates anti-CSRF tokens solely for HTTP POST requests, while GET-based declarative guards run only when an `act` parameter is present in the query string. Consequently, custom backend actions dispatched via alternative parameters such as `key=` can execute without CSRF token verification when triggered by an authenticated user.

Amit Schendel
Amit Schendel
7 views•5 min read
•about 9 hours ago•CVE-2026-107843
5.3

CVE-2026-107843: Unthrottled Activation Email Resend and Account Enumeration in Contao CMS

Contao CMS versions 4.1.0 through 5.3.49 and 5.4.0-RC1 through 5.7.11 fail to validate form submission tokens and enforce rate limiting when processing activation email resend requests via HTTP POST, enabling resource exhaustion and account state enumeration.

Amit Schendel
Amit Schendel
8 views•4 min read
•about 10 hours ago•CVE-2026-107842
5.3

CVE-2026-107842: Information Disclosure via Stale Indexing in Contao Search Module

An information disclosure vulnerability in Contao CMS allows unauthenticated site visitors to view protected page titles, URLs, and text excerpts through search queries when protected page indexing is disabled after previously being enabled.

Amit Schendel
Amit Schendel
9 views•4 min read
•about 11 hours ago•GHSA-G38J-7V97-X298
6.5

GHSA-G38J-7V97-X298: Missing Authorization Check in Vikunja CalDAV Task Relation Creation

In Vikunja prior to version 2.6.0, relation creation via the CalDAV endpoint fails to invoke the TaskRelation.CanCreate authorization check. This missing access control allows an authenticated user to establish unauthorized relationships and perform write operations against any task, provided its unique identifier (UID) is known.

Alon Barad
Alon Barad
10 views•5 min read
•about 12 hours ago•GHSA-3HC7-R24J-RPWC
6.8

GHSA-3hc7-r24j-rpwc: Cross-Project Task Disclosure via Subtask Expansion in Vikunja

A cross-project information disclosure vulnerability in Vikunja allows authenticated users with read access to one project to view private task details from unauthorized projects via subtask expansion parameters.

Alon Barad
Alon Barad
9 views•5 min read