GHSA-cg87-wmx4-v546
KaTeX \htmlData does not validate attribute names
Quick fix
GHSA-cg87-wmx4-v546 — katex: upgrade to the fixed version with the command below.
npm install katex@0.16.21Details
### Impact KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input using `\htmlData` that runs arbitrary JavaScript, or generate invalid HTML.
### Patches Upgrade to KaTeX v0.16.21 to remove this vulnerability.
### Workarounds - Avoid use of or turn off the `trust` option, or set it to forbid `\htmlData` commands. - Forbid inputs containing the substring `"\\htmlData"`. - Sanitize HTML output from KaTeX.
### Details `\htmlData` did not validate its attribute name argument, allowing it to generate invalid or malicious HTML that runs scripts.
### For more information If you have any questions or comments about this advisory:
- Open an issue or security advisory in the [KaTeX repository](https://github.com/KaTeX/KaTeX/) - Email us at [katex-security@mit.edu](mailto:katex-security@mit.edu)
Are you affected?
Enter the version of the package you're using.