Files
open-webui/src/lib
Classic298andmaxntv bc600d3f08 fix: escape KaTeX render-error fallback to prevent XSS via {@html} (#26718)
KatexRenderer rendered the raw math source through {@html} whenever renderToString threw. throwOnError only suppresses KaTeX ParseError, so a RangeError (maximum call stack size exceeded, reachable with deeply-nested brace input) escaped into the catch and re-exposed the unescaped source. Because the math tokenizer captures everything between the delimiters verbatim, that source can carry an HTML/JS payload which then executed in the viewer's browser on the application origin, a stored, cross-user XSS reachable through normal chat/channel/shared-chat rendering. Escape the fallback so the source is shown as text and is never injected as HTML. Valid math is unaffected, it still renders through the success path.

Co-authored-by: maxntv <maxntv@users.noreply.github.com>
2026-07-27 01:36:41 -04:00
..
2026-07-26 23:54:16 -04:00
2026-07-26 18:06:03 -04:00
2026-07-27 01:22:08 -04:00
2026-07-27 00:12:47 -04:00
2026-07-26 21:12:14 -04:00
2026-03-24 16:20:29 -05:00
2026-07-27 01:05:52 -04:00
2025-11-23 20:15:52 -05:00
…
2026-07-15 04:52:06 -04:00
2026-07-27 01:03:10 -04:00