Vulnerability GHSA-f98w-7cxr-ff2h
Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
March 25, 2024 at 07:38 PM UTC
KaTeX's `\includegraphics` does not escape filename
0.11.0 - 0.16.9
0.11.0 - 0.16.9
Summary
KaTeX's `\includegraphics` does not escape filename
Details
Impact
KaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML.
Patches
Upgrade to KaTeX v0.16.10 to remove this vulnerability.
Workarounds
- Avoid use of or turn off the
trustoption, or set it to forbid\includegraphicscommands. - Forbid inputs containing the substring
"\\includegraphics". - Sanitize HTML output from KaTeX.
Details
\includegraphics did not properly quote its filename argument, allowing it to generate invalid or malicious HTML that runs scripts.
For more information
If you have any questions or comments about this advisory:
- Open an issue or security advisory in the KaTeX repository
- Email us at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
8 hours ago
KaTeX: Existing prototype pollution can bypass trust restrictions
0.11.0 - 0.18.1 GHSA-238p-pmpm-9mq7
0.11.0 - 0.18.1 GHSA-238p-pmpm-9mq7
Medium Risk
1 year ago
KaTeX \htmlData does not validate attribute names
0.12.0 - 0.16.20 GHSA-cg87-wmx4-v546
0.12.0 - 0.16.20 GHSA-cg87-wmx4-v546
Medium Risk
2 years ago
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
0.11.0 - 0.16.9 GHSA-3wc5-fcw2-2329
0.11.0 - 0.16.9 GHSA-3wc5-fcw2-2329
Medium Risk
2 years ago
KaTeX's maxExpand bypassed by Unicode sub/superscripts
0.15.4 - 0.16.9 GHSA-cvr6-37gx-v8wc
0.15.4 - 0.16.9 GHSA-cvr6-37gx-v8wc
Medium Risk
2 years ago
KaTeX's maxExpand bypassed by `\edef`
0.12.0 - 0.16.9 GHSA-64fm-8hw2-v72w
0.12.0 - 0.16.9 GHSA-64fm-8hw2-v72w
Impacted packages
Timeline
Published
2 years ago
March 25, 2024 at 07:38 PM UTC
Fixed (0.16.10)
2 years ago
March 24, 2024 at 10:12 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC