CVE-2026-103923
Received Received - Intake

Prototype Pollution in KaTeX JavaScript Library

Vulnerability report for CVE-2026-103923, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object's prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
khanacademy katex to 0.18.2 (inc)
katex katex to 0.18.1 (inc)
katex katex 0.18.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-807 The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a prototype pollution vulnerability in KaTeX versions 0.11.0 to 0.18.1 where attackers can inherit properties from Object.prototype to bypass trust restrictions. This allows malicious mathematical expressions to enable trusted rendering by default, leading to cross-site scripting (XSS) via user-interaction links or loading external resources.

Detection Guidance

Detecting this vulnerability requires checking if your KaTeX version is between 0.11.0 and 0.18.1. Run: npm list katex or check package.json for the version. If using a CDN, inspect the loaded KaTeX script URL for versions in this range. Additionally, check if Object.prototype has unexpected properties like trust, default, or processor using: node -e "console.log(Object.prototype.hasOwnProperty.call(Object.prototype, 'trust'))"

If you suspect prototype pollution, audit your application for untrusted input handling in renderer options. Use browser developer tools to inspect KaTeX-generated HTML for suspicious links or external resource loads.

Impact Analysis

If you use KaTeX in your application and it processes untrusted input for renderer options without sanitization, attackers could exploit this to inject malicious scripts or load external resources. This requires the attacker to control the options object's prototype or have prototype pollution in the environment.

Compliance Impact

This vulnerability could lead to XSS attacks, which may result in unauthorized data access or modification, violating GDPR's integrity and confidentiality principles. For HIPAA, it could expose protected health information if exploited in healthcare applications.

Mitigation Strategies

Upgrade KaTeX to version 0.18.2 or later immediately. If upgrading is not possible, delete polluted properties from Object.prototype before KaTeX usage: delete Object.prototype.trust; delete Object.prototype.default; delete Object.prototype.processor.

Avoid passing untrusted input to KaTeX renderer options. Sanitize all KaTeX-generated HTML before inserting it into the DOM to prevent XSS or external resource loading. Review third-party integrations for prototype pollution risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103923. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart