Prototype Pollution Vulnerability in KaTeX JavaScript Library
CVE-2026-103923

2.1LOW

Key Information:

Vendor

Katex

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103923?

The KaTeX library, utilized for rendering TeX math on the web, has a vulnerability that affects versions 0.11.0 through 0.18.2. This flaw arises from the way the library handles renderer option objects, allowing attacker-controlled properties to be accessed. Attackers can exploit this weakness when Object.prototype is compromised, enabling the use of malicious mathematical expressions that can lead to trusted rendering, potentially allowing cross-site scripting or the loading of external resources within applications that do not properly sanitize KaTeX output. This issue has been addressed in version 0.18.2.

Affected Version(s)

KaTeX >= 0.11.0, < 0.18.2

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.