Executive brief
KaTeX is a popular JavaScript mathematics rendering library. An attacker can inject malicious code into LaTeX math expressions using the `\includegraphics` command with unescaped filenames, causing the library to generate invalid or malicious HTML that executes arbitrary JavaScript. This affects any application that renders untrusted mathematical input with KaTeX's trust option enabled.
Technical details
The vulnerability is an output encoding flaw (CWE-116) where KaTeX's `\includegraphics` command fails to properly quote or escape the filename argument when generating HTML. An authenticated attacker (or any user in a context where the trust option is enabled) can craft malicious LaTeX input containing specially crafted filenames to break out of the HTML context and inject script tags or events. The attack requires network access and the target application to have KaTeX's trust option enabled or set to allow `\includegraphics` commands. Successful exploitation allows arbitrary JavaScript execution in the context of the victim's browser. The vulnerability was patched in KaTeX v0.16.10; users should upgrade immediately or disable the trust option and sanitize HTML output.
Affected products
- KaTeX KaTeX >= 0.11.0, < 0.16.10
Timeline
- 2024-03-25: disclosed
- 2024-03-25: patched: KaTeX v0.16.10 released