Skip to content

Commit 035ff22

Browse files
authored
Merge pull request #29 from yy0931/master
Fix XSS in equation numbers
2 parents 61e637f + 4480d65 commit 035ff22

File tree

1 file changed

+11
-6
lines changed

1 file changed

+11
-6
lines changed

texmath.js

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,15 @@
44
*--------------------------------------------------------------------------------------------*/
55
'use strict';
66

7+
function escapeHTML(text) {
8+
return text
9+
.replace(/&/g, "&")
10+
.replace(/</g, "&lt;")
11+
.replace(/>/g, "&gt;")
12+
.replace(/"/g, "&quot;")
13+
.replace(/'/g, "&#039;");
14+
}
15+
716
function texmath(md, options) {
817
const delimiters = options && options.delimiters || 'dollars';
918
const outerSpace = options && options.outerSpace || false; // inline rules, effectively `dollars` require surrounding spaces, i.e ` $\psi$ `, to be accepted as inline formulas. This is primarily a guard against misinterpreting single `$`'s in normal markdown text (relevant for inline math only. Default: `false`, for backwards compatibility).
@@ -30,7 +39,7 @@ function texmath(md, options) {
3039

3140
for (const rule of texmath.rules[delimiters].block) {
3241
md.block.ruler.before('fence', rule.name, texmath.block(rule)); // ! important for ```math delimiters
33-
md.renderer.rules[rule.name] = (tokens, idx) => rule.tmpl.replace(/\$2/,tokens[idx].info) // equation number .. ?
42+
md.renderer.rules[rule.name] = (tokens, idx) => rule.tmpl.replace(/\$2/,escapeHTML(tokens[idx].info)) // equation number .. ?
3443
.replace(/\$1/,texmath.render(tokens[idx].content,true,katexOptions));
3544
}
3645
}
@@ -110,11 +119,7 @@ texmath.render = function(tex,displayMode,options) {
110119
res = texmath.katex.renderToString(tex, options);
111120
}
112121
catch(err) {
113-
res = `${tex}:${err.message}`
114-
.replace(/</g, "&lt;")
115-
.replace(/>/g, "&gt;")
116-
.replace(/"/g, "&quot;")
117-
.replace(/'/g, "&#039;");
122+
res = escapeHTML(`${tex}:${err.message}`)
118123
}
119124
return res;
120125
}

0 commit comments

Comments
 (0)