CVSS 3.1 Score 6.5 of 10 (medium)


Published Mar 25, 2024
Updated: Mar 26, 2024
CWE ID 674


CVE-2024-28244 is a vulnerability in the KaTeX JavaScript library, which is used for TeX math rendering on the web. This vulnerability allows an attacker to bypass the limit set by the "maxExpand" option and cause a near-infinite loop by using malicious input with "\def" or "\newcommand". The issue arises from the support for "Unicode (sub|super)script characters", which allows each sub/superscript group to instantiate a separate Parser without inheriting the macro execution count from its parent. This vulnerability has been addressed in KaTeX version 0.16.10. It has a base severity of MEDIUM and an exploitability score of 2.8, with LOW privileges required and no user interaction needed. The attack vector is through the network, and it poses a high availability impact on affected organizations.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-28244 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options