Prototype Pollution Vulnerability in KaTeX JavaScript Library
CVE-2026-103923
2.1LOW
What is CVE-2026-103923?
The KaTeX library, utilized for rendering TeX math on the web, has a vulnerability that affects versions 0.11.0 through 0.18.2. This flaw arises from the way the library handles renderer option objects, allowing attacker-controlled properties to be accessed. Attackers can exploit this weakness when Object.prototype is compromised, enabling the use of malicious mathematical expressions that can lead to trusted rendering, potentially allowing cross-site scripting or the loading of external resources within applications that do not properly sanitize KaTeX output. This issue has been addressed in version 0.18.2.
Affected Version(s)
KaTeX >= 0.11.0, < 0.18.2
