An open index of dependabot pull requests across open source projects.

katex

Ecosystem:
npm
Package URL:
pkg:npm/katex
Total PRs:
5,685 Dependabot PRs
Latest PR:
1 day ago
Unique Repositories:
2,442 repositories
Unique Repos (30 days):
75 repositories
Security Advisories
KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols
GHSA-3wc5-fcw2-2329 CVE-2024-28246 MODERATE published about 2 years ago • updated about 1 month ago
### Impact Code that uses KaTeX's `trust` option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs...
KaTeX's maxExpand bypassed by `\edef`
GHSA-64fm-8hw2-v72w CVE-2024-28243 MODERATE published about 2 years ago • updated about 1 month ago
### Impact KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop...
KaTeX's maxExpand bypassed by Unicode sub/superscripts
GHSA-cvr6-37gx-v8wc CVE-2024-28244 MODERATE published about 2 years ago • updated 6 days ago
### Impact KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\def` or `\newcommand` that causes a ne...
KaTeX \htmlData does not validate attribute names
GHSA-cg87-wmx4-v546 CVE-2025-23207 MODERATE published over 1 year ago • updated 7 days ago
### Impact KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input using `\htmlData` that r...
KaTeX's `\includegraphics` does not escape filename
GHSA-f98w-7cxr-ff2h CVE-2024-28245 MODERATE published about 2 years ago • updated 7 days ago
### Impact KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary J...
Recent PRs
Bump katex from 0.16.0 to 0.17.0

steuxnet/doks #309

0.16.0 → 0.17.0 Minor PR
Open 16 days ago 1 comment
steuxnet
Package Details
Name: katex
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/katex
JSON API: View JSON
Security Advisories

5

Active advisories
MODERATE 5
View All npm Advisories
Package Information
Description:

Fast math typesetting for the web.

Repository: https://github.com/KaTeX/KaTeX
Homepage: https://katex.org
Latest Release: 0.16.22
about 1 year ago
Dependent Repos: 23,138
Dependent Packages: 1,186
Downloads: 10,889,424
Ranking: Top 0.1951% by dependent repos Top 0.158% by downloads Top 0.0649% by dependent pkgs
PR Status
Open 2,713 (47.7%)
Merged 100 (1.8%)
Closed 2,684 (47.2%)
PR Types
Minor 250 (4.4%)
Patch 5,247 (92.3%)