Skip to content

fix(deps): update dependency katex to ^0.18.0 [security] - #1975

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-katex-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-katex-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
katex (source) ^0.16.11 → ^0.18.0 age confidence

KaTeX: Existing prototype pollution can bypass trust restrictions

CVE-2026-103923 / GHSA-238p-pmpm-9mq7

More information

Details

Impact

KaTeX can act as a read-side prototype pollution gadget in applications where Object.prototype has already been polluted, or where an attacker can influence the prototype of the renderer options object. (KaTeX does not enable said prototype pollution. This advisory applies when combining KaTeX with other vulnerable software that allows for prototype pollution.)

Affected versions may treat inherited properties from Object.prototype as renderer options, internal setting metadata, or namespace entries. In particular, an inherited trust value will be treated as though the application explicitly enabled trusted rendering, rather than using the documented default of false.

With attacker-controlled mathematical expressions, this can produce links capable of user-interaction cross-site scripting or load attacker-selected external resources. Exploitation requires the consuming application to insert KaTeX output into a web page without a separate sanitizer. (KaTeX does not execute scripts merely by rendering an expression.)

Other inherited settings can alter rendering behavior or resource limits. Inherited setting metadata can affect how defaults and supplied options are processed, while inherited namespace properties can be mistaken for defined macros or other internal values.

Patches

Upgrade to KaTeX v0.18.2 to remove this vulnerability.

Workarounds
  • Address any prototype-pollution vulnerability in the application or its dependencies.
  • delete Object.prototype.trust, delete Object.prototype.default, and delete Object.prototype.processor before calling KaTeX
  • Do not allow untrusted input to control the renderer options object or its prototype.
  • Sanitize KaTeX-generated HTML before inserting it into a document.
Details

KaTeX previously used ordinary JavaScript property access in the following contexts:

  • Renderer settings could be inherited from the prototype of the options object.
  • Internal default and processor setting metadata could be inherited from Object.prototype.
  • Namespace lookup could treat inherited properties as built-in definitions.
  • Namespace group restoration could preserve an inherited property as though it had been an explicitly defined value.

The fix adds own-property checks to each of these paths. Inherited properties are no longer accepted as renderer settings, setting metadata, namespace definitions, or values to be restored after a group ends.

For more information

If you have any questions or comments about this advisory:

Severity

  • CVSS Score: 2.1 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

KaTeX/KaTeX (katex)

v0.18.2

Compare Source

Bug Fixes

v0.18.1

Compare Source

Features

v0.18.0

Compare Source

Features
BREAKING CHANGES
  • users who apply custom styles or have allowlists targeting KaTeX's internal classes must update their selectors.

v0.17.0

Compare Source

Performance Improvements
  • simplify defineFunction to avoid destructuring, improve typing (#​4222) (fb604e6)
BREAKING CHANGES
  • The internal API for __defineFunction changed: you should no longer wrap properties in props.

0.16.47 (2026-05-16)

Bug Fixes

0.16.46 (2026-05-13)

Bug Fixes

0.16.45 (2026-04-05)

Bug Fixes

0.16.44 (2026-03-27)

Bug Fixes
  • remove extra \jot space at bottom of align/gather/etc. (#​4184) (3870ee9)

0.16.43 (2026-03-26)

Bug Fixes
  • use makeEm() consistently to truncate long CSS decimals (#​4181) (0967dcc)

0.16.42 (2026-03-24)

Features

0.16.41 (2026-03-24)

Bug Fixes

0.16.40 (2026-03-20)

Bug Fixes

0.16.39 (2026-03-19)

Bug Fixes

0.16.38 (2026-03-08)

Bug Fixes

0.16.37 (2026-03-06)

Bug Fixes

0.16.36 (2026-03-06)

Bug Fixes

0.16.35 (2026-03-05)

Bug Fixes

0.16.34 (2026-03-05)

Bug Fixes

0.16.33 (2026-02-23)

Bug Fixes

0.16.32 (2026-02-22)

Bug Fixes

0.16.31 (2026-02-22)

Bug Fixes

0.16.30 (2026-02-22)

Bug Fixes

0.16.29 (2026-02-22)

Bug Fixes

0.16.28 (2026-01-25)

Bug Fixes
  • type: add missing types definition path to package.json (#​4125) (0ef8921)

0.16.27 (2025-12-07)

Features
  • support equals sign and surrounding whitespace in \htmlData attribute values (#​4112) (c77aaec)

0.16.26 (2025-12-07)

Bug Fixes
  • \mathop followed by integral symbol (6fbad18)

0.16.25 (2025-10-13)

Features

0.16.24 (2025-10-12)

Features

0.16.23 (2025-10-03)

Bug Fixes

0.16.22 (2025-04-09)

Bug Fixes

0.16.21 (2025-01-17)

Bug Fixes
  • escape \htmlData attribute name (57914ad)

0.16.20 (2025-01-12)

Bug Fixes

0.16.19 (2024-12-29)

Bug Fixes

0.16.18 (2024-12-18)

Bug Fixes

0.16.17 (2024-12-17)

Bug Fixes
  • MathML combines multidigit numbers with sup/subscript, comma separators, and multicharacter text when outputting to DOM (#​3999) (7d79e22), closes #​3995

0.16.16 (2024-12-17)

Features

0.16.15 (2024-12-09)

Features
  • italic sans-serif in math mode via \mathsfit command (#​3998) (2218901)

0.16.14 (2024-12-08)

Features

0.16.13 (2024-12-08)

Bug Fixes

0.16.12 (2024-12-08)

Features

0.16.11 (2024-07-02)

Features

0.16.10 (2024-03-24)

Bug Fixes

0.16.9 (2023-10-02)

Features

0.16.8 (2023-06-24)

Features
  • expose error length and raw error message on ParseError (#​3820) (710774a)

0.16.7 (2023-04-28)

Bug Fixes

0.16.6 (2023-04-17)

Bug Fixes

0.16.5 (2023-04-17)

Features

0.16.4 (2022-12-07)

Bug Fixes

0.16.3 (2022-10-22)

Bug Fixes

0.16.2 (2022-08-29)

Bug Fixes

0.16.1 (2022-08-28)

Bug Fixes

Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (1)
  • coderabbit-review-active

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: Zoo-Code-Org/Zoo-Code/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 7df2d549-e174-42c2-b19f-3831d422e440

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review status

This PR was opened by an automated account. A human maintainer must verify the change intent, provenance, and validation before merging.

Current step: Awaiting fresh human maintainer or CODEOWNER approval.

Review-state labels are managed by this workflow; do not edit them manually. community-approved is managed the same way — do not add or remove it manually. It signals a fresh community code approval for the current head as an advisory priority only; maintainer review is still required.

@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-actions github-actions Bot added the awaiting-maintainer CodeRabbit approved; waiting for a human maintainer label Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting-maintainer CodeRabbit approved; waiting for a human maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants