MEDIUM5.5npm
GHSA-3wc5-fcw2-2329· CVE-2024-28246KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
Modified: 9/10/2026
package
pkg:npm/katex
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
Modified: 9/10/2026
KaTeX's maxExpand bypassed by `\edef`
Modified: 2/5/2026
KaTeX \htmlData does not validate attribute names
Modified: 1/21/2025
KaTeX's maxExpand bypassed by Unicode sub/superscripts
Modified: 9/10/2026
KaTeX's `\includegraphics` does not escape filename
Modified: 9/10/2026