Ctan maintains a small portfolio of mathematical typesetting and rendering tools, including MathTeX and MimeTeX, that process untrusted mathematical markup input from web applications and documents. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through dangerous input-handling weakness classes—buffer overflows, command injection, code injection, infinite loops, and out-of-bounds writes—that reflect the parsing complexity inherent to converting mathematical notation into rendered output. Defenders deploying these tools should treat input sanitization as essential and monitor for patches addressing parsing and code-generation flaws; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ctan over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40446CRITICAL An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script | Apr 22, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-51889CRITICAL Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL. | Jan 24, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-51887CRITICAL Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL. | Jan 24, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51885CRITICAL Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component. | Jan 24, 2024 | 9.8 | 24 | NO | NO |
CVE-2023-51890HIGH An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL. | Jan 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-51888HIGH Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application UR | Jan 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-51886HIGH Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath. | Jan 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-40445HIGH A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input path | Apr 22, 2025 | 7.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ctan.
Media articles that mention a CVE ID that affects a product developed by Ctan — matched by CVE ID, not by vendor name.