[Bugcrowd] Stored XSS via Latex Input

Description

Note from QA:

The issue has been successfully reproduced on both QA and PROD environments. It affects both regular and inline macro versions.

The below description has been copied from the original bugcrowd submission.

Issue

Hello,
I found an stored XSS vulnerability via Latex Input. As an attacker, I can enter a phishing/malware website or take JWT auth. If successful, a XSS attack can severely impact websites and web applications, damage reputation and relationships with customers. XSS can deface websites, can result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.

Payload :

$$\href{javascript:alert(location.href)}{Click me}$$

Steps to reproduce

  1. Go to blogs/pages and choose Macro Pack

  2. Choose Latex Input with Source Text Input and then fill with payload

  3. Insert

  4. When victim click link, XSS will popup

Impact

  • Account takeover or JWT auth takeover

  • If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user.

  • Create phishing/malware website.

Activity

Adam Lipiński 10 August 2026, 19:33

QA pass completed, issue is fixed and no regressions found. Ready to merge. :check_mark: