CVE-2024-28246
MEDIUMDescription
KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) => context.protocol !== 'javascript'`. Upgrade to KaTeX v0.16.10 to remove this vulnerability.
Is your site exposed to CVE-2024-28246?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| katex | katex |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-28246? +
How severe is CVE-2024-28246? +
What products are affected by CVE-2024-28246? +
How do I check if I'm vulnerable to CVE-2024-28246? +
Related Vulnerabilities
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior …
An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. …
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by …
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, …
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create …
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From …