Description
KaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML.
Recommendation
Update the katex package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.11.0, < 0.16.10
- Patched version(s): 0.16.10
References
Related Issues
- KaTeX \htmlData does not validate attribute names - CVE-2025-23207
- Svelte SSR does not validate dynamic element tag names in `<svelte:element>` - CVE-2026-27122
- expr-eval does not restrict functions passed to the evaluate function - expr-eval - CVE-2025-12735
- @udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme - CVE-2023-34245
You might also like:
- Tags:
- npm
- katex
Anything's wrong? Let us know Last updated on March 25, 2024


