KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:49.569Z
Reserved: 2024-03-07T14:33:30.036Z
Link: CVE-2024-28245

Updated: 2024-08-01T15:39:47.585Z

Status : Awaiting Analysis
Published: 2024-03-25T20:15:08.370
Modified: 2024-11-21T09:06:05.163
Link: CVE-2024-28245

No data.