Source: node-katex
Version: 0.16.10+~cs6.1.0-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/KaTeX/KaTeX/pull/4260
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-katex.

CVE-2026-103923[0]:
| KaTeX is a fast, easy-to-use JavaScript library for TeX math
| rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary
| JavaScript property access for the renderer options object, the
| trust setting, default and processor setting metadata, and namespace
| lookup and group restoration, allowing inherited properties to be
| treated as explicitly supplied values. When Object.prototype is
| already polluted or an attacker controls the options object's
| prototype, attacker-controlled mathematical expressions can use an
| inherited trust value to enable trusted rendering and produce links
| capable of user-interaction cross-site scripting or loading
| attacker-selected external resources in a consuming application that
| inserts unsanitized KaTeX output into a page. KaTeX does not itself
| create the prototype pollution, and rendering an expression alone
| does not execute script. This issue is fixed in version 0.18.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103923
    https://www.cve.org/CVERecord?id=CVE-2026-103923
[1] https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7
[2] https://github.com/KaTeX/KaTeX/pull/4260
[3] 
https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to