GHSA-cg87-wmx4-v546 · Severity: medium · Ecosystem: npm — KaTeX \htmlData does not validate attribute names
KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions with `renderToString` could encounter malicious input using `\htmlData` that runs arbitrary JavaScript, or generate invalid HTML. Users are advised to upgrade to KaTeX v0.16.21 to remove this vulnerability. Users unable to upgrade should avoid use of or turn off the `trust` option, or set it to forbid `\htmlData` commands, forbid inputs containing the substring `"\\htmlData"` and sanitize HTML output from KaTeX.
Conclusion & alert: CVE-2025-23207 is rated Low Risk (35.9/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.38%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.38% | +0.33% |
| 2 | 2026-06-08 | 0.04% | 0.05% | +0.01% |
| 3 | 2025-11-21 | — | 0.04% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 3.1 | MEDIUM |
|
2.8 | 3.4 | [email protected] |
| 7.2 | 3.1 | HIGH |
|
3.9 | 2.7 | [email protected] |
GHSA-cg87-wmx4-v546 · Severity: medium · Ecosystem: npm — KaTeX \htmlData does not validate attribute names
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-23207 not yet assigned priority: Debian including 1 source packages (node-katex), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2025-23207 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-23207 |
ubuntu
|
medium | CVE-2025-23207 medium priority: Ubuntu including 1 source packages (node-katex), 8 status rows across 8 suites (bionic, focal, jammy, noble, oracular, plucky, questing, upstream): released 6, not-affected 2. | https://ubuntu.com/security/CVE-2025-23207 |
| URL | Tags |
|---|---|
| https://github.com/KaTeX/KaTeX/commit/ff289955e81aab89086eef09254cbf88573d415c | Patch |
| https://github.com/KaTeX/KaTeX/security/advisories/GHSA-cg87-wmx4-v546 | Third Party Advisory |