JavaScript Library Vulnerability in KaTeX by Khan Academy
CVE-2025-23207
6.3MEDIUM
What is CVE-2025-23207?
A vulnerability in the KaTeX JavaScript library allows attackers to exploit the renderToString function when rendering untrusted mathematical expressions. If the trust option is enabled, malicious input using the \htmlData command can execute arbitrary JavaScript or produce invalid HTML output. To mitigate this risk, users are strongly advised to update to KaTeX v0.16.21 or disable the trust option. Alternatively, users can sanitize inputs by disallowing the \htmlData commands or filtering out any input containing this substring.
Affected Version(s)
KaTeX >= 0.12.0, < 0.16.21
