GHSA-929m-phjg-qwcc

Suggest an improvement
Source
https://github.com/advisories/GHSA-929m-phjg-qwcc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-929m-phjg-qwcc/GHSA-929m-phjg-qwcc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-929m-phjg-qwcc
Withdrawn
2025-04-02T00:33:15Z
Published
2025-04-01T21:31:30Z
Modified
2025-04-02T00:33:15Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-qwj6-q94f-8425. This link is maintained to preserve external references.

Original Description

Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-04-02T00:33:15Z",
    "nvd_published_at": "2025-04-01T21:15:43Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / mathlive

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.104.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-929m-phjg-qwcc/GHSA-929m-phjg-qwcc.json"