KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
- Severity:
- Medium
Description
Code that uses KaTeX’s trust
option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol.
Recommendation
Update the katex
package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.11.0, < 0.16.10
- Patched version(s): 0.16.10
References
Related Issues
- KaTeX \htmlData does not validate attribute names - CVE-2025-23207
- Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string) - Vulnerability
- KaTeX's `\includegraphics` does not escape filename - CVE-2024-28245
- KaTeX's maxExpand bypassed by Unicode sub/superscripts - CVE-2024-28244
- Tags:
- npm
- katex
Anything's wrong? Let us know Last updated on March 25, 2024