mathjax / MathJax

Beautiful and accessible math in all browsers
http://www.mathjax.org/
Apache License 2.0
10.01k stars 1.16k forks source link

Github Security Lab Vulnerability Report #3249

Open Kwstubbs opened 1 week ago

Kwstubbs commented 1 week ago

Greetings MathJax maintainers,

Github has found a potentail vulnerability in MathJax. Please let us know of a point of contact so that we can discuss this privately. We have the Private Vulnerability Reporting feature if you do not have an established point of contact.

Thanks, Kevin

dpvc commented 6 days ago

I have enabled the private vulnerability reporting as you have suggested. Please report your issue there.

If it is the issue from #3241 (which is a duplicate of #3129), then we are aware of it, and have patched it in v4.0 (now out in beta). There is a workaround listed in #3129 for v3.