Source: node-katex Version: 0.16.10+~cs6.1.0-2 Severity: important Tags: security upstream Forwarded: https://github.com/KaTeX/KaTeX/pull/4260 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-katex. CVE-2026-103923[0]: | KaTeX is a fast, easy-to-use JavaScript library for TeX math | rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary | JavaScript property access for the renderer options object, the | trust setting, default and processor setting metadata, and namespace | lookup and group restoration, allowing inherited properties to be | treated as explicitly supplied values. When Object.prototype is | already polluted or an attacker controls the options object's | prototype, attacker-controlled mathematical expressions can use an | inherited trust value to enable trusted rendering and produce links | capable of user-interaction cross-site scripting or loading | attacker-selected external resources in a consuming application that | inserts unsanitized KaTeX output into a page. KaTeX does not itself | create the prototype pollution, and rendering an expression alone | does not execute script. This issue is fixed in version 0.18.2. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-103923 https://www.cve.org/CVERecord?id=CVE-2026-103923 [1] https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7 [2] https://github.com/KaTeX/KaTeX/pull/4260 [3] https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4 Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
