KaTeX Fixes Security Vulnerability in Math Rendering Library
CVE-2024-28245

6.3MEDIUM

Key Information:

Vendor

Katex

Status
Vendor
CVE Published:
25 March 2024

What is CVE-2024-28245?

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using \includegraphics that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability.

Affected Version(s)

KaTeX >= 0.11.0, < 0.6.10

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.