Vulnerability GHSA-cg87-wmx4-v546

Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
January 17, 2025 at 09:22 PM UTC
KaTeX \htmlData does not validate attribute names
0.12.0 - 0.16.20
0.12.0 - 0.16.20

Summary

KaTeX \htmlData does not validate attribute names

Details

Impact

KaTeX users who render untrusted mathematical expressions with renderToString could encounter malicious input using \htmlData that runs arbitrary JavaScript, or generate invalid HTML.

Patches

Upgrade to KaTeX v0.16.21 to remove this vulnerability.

Workarounds

  • Avoid use of or turn off the trust option, or set it to forbid \htmlData commands.
  • Forbid inputs containing the substring "\\htmlData".
  • Sanitize HTML output from KaTeX.

Details

\htmlData did not validate its attribute name argument, allowing it to generate invalid or malicious HTML that runs scripts.

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
1 year ago
January 17, 2025 at 09:22 PM UTC
Fixed (0.16.21)
1 year ago
January 17, 2025 at 08:30 PM UTC
Last Modified
1 year ago
January 21, 2025 at 06:31 PM UTC