CVE-2025-23207
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Summary
CVE-2025-23207 is a vulnerability affecting KaTeX, a JavaScript library used for rendering TeX math expressions on the web. This issue allows attackers to inject arbitrary JavaScript code or generate invalid HTML by providing malicious input to the `renderToString` function using the `\\htmlData` command. KaTeX users are encouraged to upgrade to version 0.16.21 to mitigate this issue. For those unable to upgrade, disabling or setting the `trust` option to forbid `\\htmlData` commands, and sanitizing HTML output from KaTeX are recommended as temporary measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.