GHSA-f98w-7cxr-ff2h
KaTeX's `\includegraphics` does not escape filename
Quick fix
GHSA-f98w-7cxr-ff2h — katex: upgrade to the fixed version with the command below.
npm install katex@0.16.10Details
### Impact KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML.
### Patches Upgrade to KaTeX v0.16.10 to remove this vulnerability.
### Workarounds * Avoid use of or turn off the `trust` option, or set it to forbid `\includegraphics` commands. * Forbid inputs containing the substring `"\\includegraphics"`. * Sanitize HTML output from KaTeX.
### Details `\includegraphics` did not properly quote its filename argument, allowing it to generate invalid or malicious HTML that runs scripts.
### For more information If you have any questions or comments about this advisory:
* Open an issue or security advisory in the [KaTeX repository](https://github.com/KaTeX/KaTeX/) * Email us at katex-security@mit.edu
Are you affected?
Enter the version of the package you're using.