KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
- Severity:
- Medium
Description
Code that uses KaTeX’s trust option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol.
Recommendation
Update the katex package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.11.0, < 0.16.10
- Patched version(s): 0.16.10
References
Related Issues
- Elliptic's ECDSA missing check for whether leading bit of r and s is zero - CVE-2024-42460
- Elliptic's EDDSA missing signature length check - CVE-2024-42459
- Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click - CVE-2026-43941
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818
You might also like:
- Tags:
- npm
- katex
Anything's wrong? Let us know Last updated on March 25, 2024


