Adr viewer: Mistune Math Plugin has an XSS Escape Bypass (CVE-2026-44708)
The Adr viewer's Mistune math plugin (versions >=1.3.0 <1.4.0_5) has a cross-site scripting (XSS) vulnerability due to improper escaping of user input within math delimiters. The plugin renders inline and block math by directly concatenating raw user content into HTML without escaping, even when the parser is configured with escape=True. This allows malicious HTML or script code inside math delimiters to be injected and executed in the browser.
AI Analysis
Technical Summary
The Mistune math plugin in Adr viewer bypasses the escape=True setting by rendering inline math ($...$) and block math ($$...$$) content without any HTML escaping. The plugin's render functions directly concatenate raw user input into the HTML output, ignoring the renderer's escape flag and not calling any sanitization functions. This results in a silent contract violation where developers expect XSS protection but receive none inside math delimiters. Proof-of-concept shows script tags and event handlers can execute when embedded inside math delimiters. The vulnerability affects Adr viewer versions >=1.3.0 and <1.4.0_5 and has a CVSS 3.1 score of 6.1 (medium severity). A patch is available.
Potential Impact
An attacker can inject malicious HTML or JavaScript code inside math delimiters in markdown content processed by the Adr viewer's Mistune math plugin. This code is rendered unescaped in the browser, enabling cross-site scripting attacks that can lead to information disclosure (e.g., cookie theft) and other client-side impacts. The vulnerability violates the expected escape contract, potentially misleading developers about the safety of user input within math expressions.
Mitigation Recommendations
A patch is available for Adr viewer versions >=1.3.0 <1.4.0_5 that fixes this vulnerability by properly escaping user input in the math plugin render functions. Users should upgrade to the fixed version as soon as possible. Until patched, avoid enabling or using the math plugin with untrusted user input or disable math rendering to prevent XSS risks.
Adr viewer: Mistune Math Plugin has an XSS Escape Bypass (CVE-2026-44708)
Description
The Adr viewer's Mistune math plugin (versions >=1.3.0 <1.4.0_5) has a cross-site scripting (XSS) vulnerability due to improper escaping of user input within math delimiters. The plugin renders inline and block math by directly concatenating raw user content into HTML without escaping, even when the parser is configured with escape=True. This allows malicious HTML or script code inside math delimiters to be injected and executed in the browser.
CVSS v3.1
Score 6.1medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Mistune math plugin in Adr viewer bypasses the escape=True setting by rendering inline math ($...$) and block math ($$...$$) content without any HTML escaping. The plugin's render functions directly concatenate raw user input into the HTML output, ignoring the renderer's escape flag and not calling any sanitization functions. This results in a silent contract violation where developers expect XSS protection but receive none inside math delimiters. Proof-of-concept shows script tags and event handlers can execute when embedded inside math delimiters. The vulnerability affects Adr viewer versions >=1.3.0 and <1.4.0_5 and has a CVSS 3.1 score of 6.1 (medium severity). A patch is available.
Potential Impact
An attacker can inject malicious HTML or JavaScript code inside math delimiters in markdown content processed by the Adr viewer's Mistune math plugin. This code is rendered unescaped in the browser, enabling cross-site scripting attacks that can lead to information disclosure (e.g., cookie theft) and other client-side impacts. The vulnerability violates the expected escape contract, potentially misleading developers about the safety of user input within math expressions.
Mitigation Recommendations
A patch is available for Adr viewer versions >=1.3.0 <1.4.0_5 that fixes this vulnerability by properly escaping user input in the math plugin render functions. Users should upgrade to the fixed version as soon as possible. Until patched, avoid enabling or using the math plugin with untrusted user input or disable math rendering to prevent XSS risks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-adr-viewer-CVE-2026-44708
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac8e1855bf5e2cf549043d
Added to database: 09/18/2026, 01:04:24 UTC
Last enriched: 09/18/2026, 01:36:17 UTC
Last updated: 09/18/2026, 02:08:49 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.