Vulnerabilities/

KaTeX \htmlData does not validate attribute names

Severity:
Medium

Description

KaTeX users who render untrusted mathematical expressions with renderToString could encounter malicious input using \htmlData that runs arbitrary JavaScript, or generate invalid HTML.

Recommendation

Update the katex package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
katex
Anything's wrong? Let us know Last updated on September 10, 2025

This issue is available in SmartScanner Professional

See Pricing