⬆️(dependencies) update katex to v0.16.21 [SECURITY]#2682
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
⬆️(dependencies) update katex to v0.16.21 [SECURITY]#2682renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
1b47636 to
87e997c
Compare
1f1554f to
56cdb76
Compare
659f4b6 to
1152d50
Compare
10f0db9 to
db9245e
Compare
d0449f0 to
5b1d5f2
Compare
5b1d5f2 to
71ade64
Compare
02917db to
e5bfbc7
Compare
9c174a7 to
a5e8839
Compare
a5e8839 to
320639c
Compare
32be69f to
558f001
Compare
2f04669 to
e18bb1b
Compare
105e3c9 to
06bdd8e
Compare
8afc4c5 to
8ac3c67
Compare
7576c66 to
d5c6f0d
Compare
d5c6f0d to
c246a40
Compare
c246a40 to
48d7f12
Compare
aa80313 to
894b5ed
Compare
d0bfb57 to
abdd940
Compare
abdd940 to
83d5f06
Compare
83d5f06 to
9b3c13a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.16.19→0.16.21GitHub Vulnerability Alerts
CVE-2025-23207
Impact
KaTeX users who render untrusted mathematical expressions with
renderToStringcould encounter malicious input using\htmlDatathat runs arbitrary JavaScript, or generate invalid HTML.Patches
Upgrade to KaTeX v0.16.21 to remove this vulnerability.
Workarounds
trustoption, or set it to forbid\htmlDatacommands."\\htmlData".Details
\htmlDatadid not validate its attribute name argument, allowing it to generate invalid or malicious HTML that runs scripts.For more information
If you have any questions or comments about this advisory:
Release Notes
KaTeX/KaTeX (katex)
v0.16.21Compare Source
Bug Fixes
v0.16.20Compare Source
Bug Fixes
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.