CVE-2025-23207
Publication date 17 January 2025
Last updated 18 June 2025
Ubuntu priority
Cvss 3 Severity Score
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input using `\htmlData` that runs arbitrary JavaScript, or generate invalid HTML. Users are advised to upgrade to KaTeX v0.16.21 to remove this vulnerability. Users unable to upgrade should avoid use of or turn off the `trust` option, or set it to forbid `\htmlData` commands, forbid inputs containing the substring `"\\htmlData"` and sanitize HTML output from KaTeX.
Status
Package | Ubuntu Release | Status |
---|---|---|
node-katex | 25.04 plucky |
Fixed 0.16.10+~cs6.1.0-2ubuntu0.25.04.1
|
24.10 oracular |
Fixed 0.16.10+~cs6.1.0-2ubuntu0.24.10.1
|
|
24.04 LTS noble |
Fixed 0.16.10+~cs6.1.0-2ubuntu0.24.04.1~esm1
|
|
22.04 LTS jammy |
Fixed 0.13.11+~cs6.0.0-2ubuntu0.1~esm1
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | Low |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
References
Related Ubuntu Security Notices (USN)
- USN-7572-1
- KaTeX vulnerabilities
- 17 June 2025