CVE-2025-23207: KaTeX \htmlData does not validate attribute names
KaTeX users who render untrusted mathematical expressions with renderToString
could encounter malicious input using \htmlData
that runs arbitrary JavaScript, or generate invalid HTML.
References
Detect and mitigate CVE-2025-23207 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →