JavaScript Library Vulnerability in KaTeX by Khan Academy
CVE-2025-23207

6.3MEDIUM

Key Information:

Vendor

Katex

Status
Vendor
CVE Published:
17 January 2025

What is CVE-2025-23207?

A vulnerability in the KaTeX JavaScript library allows attackers to exploit the renderToString function when rendering untrusted mathematical expressions. If the trust option is enabled, malicious input using the \htmlData command can execute arbitrary JavaScript or produce invalid HTML output. To mitigate this risk, users are strongly advised to update to KaTeX v0.16.21 or disable the trust option. Alternatively, users can sanitize inputs by disallowing the \htmlData commands or filtering out any input containing this substring.

Affected Version(s)

KaTeX >= 0.12.0, < 0.16.21

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.