Repository navigation
fix(deps): update dependency katex to ^0.18.0 [security] - #1975
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Review statusThis PR was opened by an automated account. A human maintainer must verify the change intent, provenance, and validation before merging. Current step: Awaiting fresh human maintainer or CODEOWNER approval. Review-state labels are managed by this workflow; do not edit them manually. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This PR contains the following updates:
^0.16.11→^0.18.0KaTeX: Existing prototype pollution can bypass trust restrictions
CVE-2026-103923 / GHSA-238p-pmpm-9mq7
More information
Details
Impact
KaTeX can act as a read-side prototype pollution gadget in applications where
Object.prototypehas already been polluted, or where an attacker can influence the prototype of the renderer options object. (KaTeX does not enable said prototype pollution. This advisory applies when combining KaTeX with other vulnerable software that allows for prototype pollution.)Affected versions may treat inherited properties from
Object.prototypeas renderer options, internal setting metadata, or namespace entries. In particular, an inheritedtrustvalue will be treated as though the application explicitly enabled trusted rendering, rather than using the documented default offalse.With attacker-controlled mathematical expressions, this can produce links capable of user-interaction cross-site scripting or load attacker-selected external resources. Exploitation requires the consuming application to insert KaTeX output into a web page without a separate sanitizer. (KaTeX does not execute scripts merely by rendering an expression.)
Other inherited settings can alter rendering behavior or resource limits. Inherited setting metadata can affect how defaults and supplied options are processed, while inherited namespace properties can be mistaken for defined macros or other internal values.
Patches
Upgrade to KaTeX v0.18.2 to remove this vulnerability.
Workarounds
delete Object.prototype.trust,delete Object.prototype.default, anddelete Object.prototype.processorbefore calling KaTeXDetails
KaTeX previously used ordinary JavaScript property access in the following contexts:
defaultandprocessorsetting metadata could be inherited fromObject.prototype.The fix adds own-property checks to each of these paths. Inherited properties are no longer accepted as renderer settings, setting metadata, namespace definitions, or values to be restored after a group ends.
For more information
If you have any questions or comments about this advisory:
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
KaTeX/KaTeX (katex)
v0.18.2Compare Source
Bug Fixes
v0.18.1Compare Source
Features
strict(#4243) (4237070)v0.18.0Compare Source
Features
BREAKING CHANGES
v0.17.0Compare Source
Performance Improvements
defineFunctionto avoid destructuring, improve typing (#4222) (fb604e6)BREAKING CHANGES
__defineFunctionchanged: you should no longer wrap properties inprops.0.16.47 (2026-05-16)
Bug Fixes
[big delimiter (#4217) (7ba0027), closes #42150.16.46 (2026-05-13)
Bug Fixes
0.16.45 (2026-04-05)
Bug Fixes
0.16.44 (2026-03-27)
Bug Fixes
0.16.43 (2026-03-26)
Bug Fixes
0.16.42 (2026-03-24)
Features
0.16.41 (2026-03-24)
Bug Fixes
0.16.40 (2026-03-20)
Bug Fixes
0.16.39 (2026-03-19)
Bug Fixes
0.16.38 (2026-03-08)
Bug Fixes
0.16.37 (2026-03-06)
Bug Fixes
\hphantomand symmetric\smash(#4153) (d4799ca)0.16.36 (2026-03-06)
Bug Fixes
0.16.35 (2026-03-05)
Bug Fixes
0.16.34 (2026-03-05)
Bug Fixes
0.16.33 (2026-02-23)
Bug Fixes
0.16.32 (2026-02-22)
Bug Fixes
0.16.31 (2026-02-22)
Bug Fixes
\*fracsizing (#4137) (ef51f18)0.16.30 (2026-02-22)
Bug Fixes
\not(#4140) (2d1ba86)0.16.29 (2026-02-22)
Bug Fixes
\imathand other\html@mathmlmacros in arguments (#4139) (a850cce)0.16.28 (2026-01-25)
Bug Fixes
0.16.27 (2025-12-07)
Features
0.16.26 (2025-12-07)
Bug Fixes
0.16.25 (2025-10-13)
Features
katex-swap.cssthat usesfont-display: swap(#3940) (b3f9ce6), closes #22420.16.24 (2025-10-12)
Features
0.16.23 (2025-10-03)
Bug Fixes
\defwith arguments viamacrosoption (#4087) (80a8158)0.16.22 (2025-04-09)
Bug Fixes
0.16.21 (2025-01-17)
Bug Fixes
0.16.20 (2025-01-12)
Bug Fixes
0.16.19 (2024-12-29)
Bug Fixes
strictfunction type (#4009) (4228b4e)0.16.18 (2024-12-18)
Bug Fixes
0.16.17 (2024-12-17)
Bug Fixes
0.16.16 (2024-12-17)
Features
0.16.15 (2024-12-09)
Features
\mathsfitcommand (#3998) (2218901)0.16.14 (2024-12-08)
Features
0.16.13 (2024-12-08)
Bug Fixes
\vdotsand\rulesupport in text mode (#3997) (0e08352), closes #39900.16.12 (2024-12-08)
Features
0.16.11 (2024-07-02)
Features
0.16.10 (2024-03-24)
Bug Fixes
0.16.9 (2023-10-02)
Features
0.16.8 (2023-06-24)
Features
0.16.7 (2023-04-28)
Bug Fixes
0.16.6 (2023-04-17)
Bug Fixes
\letviamacrosoption (#3738) (bdb0be2), closes #3737 #37370.16.5 (2023-04-17)
Features
0.16.4 (2022-12-07)
Bug Fixes
0.16.3 (2022-10-22)
Bug Fixes
0.16.2 (2022-08-29)
Bug Fixes
0.16.1 (2022-08-28)
Bug Fixes
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.