KaTeX: Existing prototype pollution can bypass trust restrictions
Published Oct 1, 2026
2.1
LOWCVSS 4.0
Description
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object's prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2.
Affected products
-
- Version >= 0.11.0, < 0.18.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (4)
- https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4 x_refsource_MISC
- https://github.com/KaTeX/KaTeX/pull/4260 x_refsource_MISC
- https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2 x_refsource_MISC
- https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4 | x_refsource_MISC | |
| https://github.com/KaTeX/KaTeX/pull/4260 | x_refsource_MISC | |
| https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2 | x_refsource_MISC | |
| https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.