SA-CONTRIB-2026-195: Critical severity drupal/mathjax vulnerability
This module integrates the MathJax library into your Drupal site. MathJax is the modern JavaScript-based LaTeX rendering solution for the Internet. The module ships with library configurations that do not escape JavaScript within the TeX it formats. Notice: This release updates CDN URLs where possible and adds a system status warning for unsafe configurations. If you are unable to upgrade immediately, you can modify either the CDN URL or the custom MathJax JavaScript configuration according to the instructions in MathJax Safe-mode.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/mathjaxto a version that resolves this vulnerability.Fixed in 4.1.2 - Configuration
Enable MathJax Safe-mode by modifying the CDN URL or the custom MathJax JavaScript configuration.
MathJax Safe-mode = enabled
Event History
Frequently Asked Questions
Are sites using the module's bundled settings affected by default?
The module ships with library configurations that do not escape JavaScript within the TeX they format. The release adds a system status warning for unsafe configurations.
What condition is required for exploitation?
JavaScript must be present within TeX that is formatted using an unsafe MathJax configuration. The affected configurations do not escape that JavaScript.
What can be done if an immediate upgrade is not possible?
Modify either the MathJax CDN URL or the custom MathJax JavaScript configuration according to the MathJax Safe-mode instructions.