KaTeX is a widely deployed mathematics typesetting library that converts LaTeX notation to web-readable output, and its vulnerability footprint centers on the single product with a durable signal in output-handling and input-validation issues such as improper encoding or escaping, cross-site scripting vectors, and uncontrolled recursion during parsing. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Katex over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-23207HIGH KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter m | Jan 17, 2025 | 7.2 | 21 | NO | NO |
CVE-2024-28244MEDIUM KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` or `\newcomm | Mar 25, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-28243MEDIUM KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes | Mar 25, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-28245MEDIUM KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` | Mar 25, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-28246MEDIUM KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically that provides a function to blacklist certain URL protocols, ca | Mar 25, 2024 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Katex.
Media articles that mention a CVE ID that affects a product developed by Katex — matched by CVE ID, not by vendor name.