Vulnerability GHSA-f98w-7cxr-ff2h

Medium Risk
MEDIUM RISK
CVSS Score: 6.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
March 25, 2024 at 07:38 PM UTC
KaTeX's `\includegraphics` does not escape filename
0.11.0 - 0.16.9
0.11.0 - 0.16.9

Summary

KaTeX's `\includegraphics` does not escape filename

Details

Impact

KaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML.

Patches

Upgrade to KaTeX v0.16.10 to remove this vulnerability.

Workarounds

  • Avoid use of or turn off the trust option, or set it to forbid \includegraphics commands.
  • Forbid inputs containing the substring "\\includegraphics".
  • Sanitize HTML output from KaTeX.

Details

\includegraphics did not properly quote its filename argument, allowing it to generate invalid or malicious HTML that runs scripts.

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
2 years ago
March 25, 2024 at 07:38 PM UTC
Fixed (0.16.10)
2 years ago
March 24, 2024 at 10:12 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC