Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/katex — 5 CVEs · VulnScope
pkg:npm/
katex
5 total CVEs
MEDIUM
5
✅ Check your installed version
Check
All known vulnerabilities
MEDIUM
6.5
CVE-2024-28244
KaTeX's maxExpand bypassed by Unicode sub/superscripts
>= 0.15.4, < 0.16.10
MEDIUM
6.5
CVE-2024-28243
KaTeX's maxExpand bypassed by `\edef`
>= 0.12.0, < 0.16.10
MEDIUM
6.3
CVE-2025-23207
KaTeX \htmlData does not validate attribute names
>= 0.12.0, < 0.16.21
MEDIUM
6.3
CVE-2024-28245
KaTeX's `\includegraphics` does not escape filename
>= 0.11.0, < 0.16.10
MEDIUM
5.5
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
>= 0.11.0, < 0.16.10
CVE-2024-28246