Vulnerabilities/

KaTeX's `\includegraphics` does not escape filename

Severity:
Medium

Description

KaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML.

Recommendation

Update the katex package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
katex
Anything's wrong? Let us know Last updated on March 25, 2024

This issue is available in SmartScanner Professional

See Pricing