Vulnerabilities/

KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols

Severity:
Medium

Description

Code that uses KaTeX’s trust option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol.

Recommendation

Update the katex package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
katex
Anything's wrong? Let us know Last updated on March 25, 2024

This issue is available in SmartScanner Professional

See Pricing