fix(deps): update dependency katex to ^0.18.0 [security] #68

Open
renovate-bot wants to merge 1 commit from renovate/npm-katex-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Confidence
katex (source) ^0.16.47 → ^0.18.0 age confidence

KaTeX: Existing prototype pollution can bypass trust restrictions

CVE-2026-103923 / GHSA-238p-pmpm-9mq7

More information

Details

Impact

KaTeX can act as a read-side prototype pollution gadget in applications where Object.prototype has already been polluted, or where an attacker can influence the prototype of the renderer options object. (KaTeX does not enable said prototype pollution. This advisory applies when combining KaTeX with other vulnerable software that allows for prototype pollution.)

Affected versions may treat inherited properties from Object.prototype as renderer options, internal setting metadata, or namespace entries. In particular, an inherited trust value will be treated as though the application explicitly enabled trusted rendering, rather than using the documented default of false.

With attacker-controlled mathematical expressions, this can produce links capable of user-interaction cross-site scripting or load attacker-selected external resources. Exploitation requires the consuming application to insert KaTeX output into a web page without a separate sanitizer. (KaTeX does not execute scripts merely by rendering an expression.)

Other inherited settings can alter rendering behavior or resource limits. Inherited setting metadata can affect how defaults and supplied options are processed, while inherited namespace properties can be mistaken for defined macros or other internal values.

Patches

Upgrade to KaTeX v0.18.2 to remove this vulnerability.

Workarounds
  • Address any prototype-pollution vulnerability in the application or its dependencies.
  • delete Object.prototype.trust, delete Object.prototype.default, and delete Object.prototype.processor before calling KaTeX
  • Do not allow untrusted input to control the renderer options object or its prototype.
  • Sanitize KaTeX-generated HTML before inserting it into a document.
Details

KaTeX previously used ordinary JavaScript property access in the following contexts:

  • Renderer settings could be inherited from the prototype of the options object.
  • Internal default and processor setting metadata could be inherited from Object.prototype.
  • Namespace lookup could treat inherited properties as built-in definitions.
  • Namespace group restoration could preserve an inherited property as though it had been an explicitly defined value.

The fix adds own-property checks to each of these paths. Inherited properties are no longer accepted as renderer settings, setting metadata, namespace definitions, or values to be restored after a group ends.

For more information

If you have any questions or comments about this advisory:

Severity

  • CVSS Score: 2.1 / 10 (Low)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).

❗ Important

Release Notes retrieval for this PR were skipped because no github.com credentials were available.
If you are self-hosted, please see this instruction.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [katex](https://katex.org) ([source](https://github.com/KaTeX/KaTeX)) | [`^0.16.47` → `^0.18.0`](https://renovatebot.com/diffs/npm/katex/0.16.47/0.18.2) | ![age](https://developer.mend.io/api/mc/badges/age/npm/katex/0.18.2?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/katex/0.16.47/0.18.2?slim=true) | --- ### KaTeX: Existing prototype pollution can bypass trust restrictions [CVE-2026-103923](https://nvd.nist.gov/vuln/detail/CVE-2026-103923) / [GHSA-238p-pmpm-9mq7](https://github.com/advisories/GHSA-238p-pmpm-9mq7) <details> <summary>More information</summary> #### Details ##### Impact KaTeX can act as a read-side prototype pollution gadget in applications where `Object.prototype` has already been polluted, or where an attacker can influence the prototype of the renderer options object. (KaTeX does not enable said prototype pollution. This advisory applies when combining KaTeX with other vulnerable software that allows for prototype pollution.) Affected versions may treat inherited properties from `Object.prototype` as renderer options, internal setting metadata, or namespace entries. In particular, an inherited `trust` value will be treated as though the application explicitly enabled trusted rendering, rather than using the documented default of `false`. With attacker-controlled mathematical expressions, this can produce links capable of user-interaction cross-site scripting or load attacker-selected external resources. Exploitation requires the consuming application to insert KaTeX output into a web page without a separate sanitizer. (KaTeX does not execute scripts merely by rendering an expression.) Other inherited settings can alter rendering behavior or resource limits. Inherited setting metadata can affect how defaults and supplied options are processed, while inherited namespace properties can be mistaken for defined macros or other internal values. ##### Patches Upgrade to KaTeX v0.18.2 to remove this vulnerability. ##### Workarounds - Address any prototype-pollution vulnerability in the application or its dependencies. - `delete Object.prototype.trust`, `delete Object.prototype.default`, and `delete Object.prototype.processor` before calling KaTeX - Do not allow untrusted input to control the renderer options object or its prototype. - Sanitize KaTeX-generated HTML before inserting it into a document. ##### Details KaTeX previously used ordinary JavaScript property access in the following contexts: - Renderer settings could be inherited from the prototype of the options object. - Internal `default` and `processor` setting metadata could be inherited from `Object.prototype`. - Namespace lookup could treat inherited properties as built-in definitions. - Namespace group restoration could preserve an inherited property as though it had been an explicitly defined value. The fix adds own-property checks to each of these paths. Inherited properties are no longer accepted as renderer settings, setting metadata, namespace definitions, or values to be restored after a group ends. ##### For more information If you have any questions or comments about this advisory: - Open an issue or security advisory in the [KaTeX repository](https://github.com/KaTeX/KaTeX/) - Email us at [katex-security@mit.edu](mailto:katex-security@mit.edu) #### Severity - CVSS Score: 2.1 / 10 (Low) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N` #### References - [https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7](https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7) - [https://nvd.nist.gov/vuln/detail/CVE-2026-103923](https://nvd.nist.gov/vuln/detail/CVE-2026-103923) - [https://github.com/KaTeX/KaTeX/pull/4260](https://github.com/KaTeX/KaTeX/pull/4260) - [https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4](https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4) - [https://github.com/KaTeX/KaTeX](https://github.com/KaTeX/KaTeX) - [https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2](https://github.com/KaTeX/KaTeX/releases/tag/v0.18.2) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-238p-pmpm-9mq7) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> > ❗ **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInNlY3VyaXR5L3Z1bG4iXX0=-->
fix(deps): update dependency katex to ^0.18.0 [security]
Some checks failed
baseline-security / baseline (push) Failing after 1m56s
scan / trivy-fs (push) Failing after 1m29s
ai-review / review (pull_request) Successful in 1m27s
baseline-security / baseline (pull_request) Failing after 1m59s
scan / trivy-fs (pull_request) Failing after 1m13s
fcc3e0df1a

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
CVE-2026-102829 (CRITICAL) @simple-git/argv-parser 1.1.1 → 2.0.1 no fix PR yet — npm update argv-parser --package-lock-only
GHSA-g2v6-rqmx-r4w6 (HIGH) @vue/server-renderer 3.5.40 → 3.5.42, 3.6.0-rc.6 no fix PR yet — npm update server-renderer --package-lock-only
CVE-2026-102276 (HIGH) brace-expansion 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-102278 (HIGH) brace-expansion 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-93687 (HIGH) braces 3.0.3 → ? no fix PR yet — npm update braces --package-lock-only
CVE-2026-92708 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-mcm9-63f2-9j32 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-r9w8-h9r3-54w4 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-x5rw-q4pp-hg5g (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
CVE-2026-85393 (HIGH) node-forge 1.4.0 → ? no fix PR yet — npm update node-forge --package-lock-only
CVE-2026-104846 (CRITICAL) seroval 1.5.6 → 1.6.2 no fix PR yet — npm update seroval --package-lock-only
CVE-2026-104845 (HIGH) seroval 1.5.6 → 1.6.3 no fix PR yet — npm update seroval --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-102828 (CRITICAL) simple-git 3.36.0 → 4.0.1 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-102826 (HIGH) simple-git 3.36.0 → 4.0.0 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-102827 (HIGH) simple-git 3.36.0 → 4.0.0 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-93749 (HIGH) source-map-js 1.2.1 → 1.2.2 no fix PR yet — npm update source-map-js --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:fcc3e0df1a2e1abfed1af713a0b55e535ca1b65c --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | CVE-2026-102829 (CRITICAL) | `@simple-git/argv-parser` | 1.1.1 → 2.0.1 | no fix PR yet — `npm update argv-parser --package-lock-only` | | GHSA-g2v6-rqmx-r4w6 (HIGH) | `@vue/server-renderer` | 3.5.40 → 3.5.42, 3.6.0-rc.6 | no fix PR yet — `npm update server-renderer --package-lock-only` | | CVE-2026-102276 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-102278 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-93687 (HIGH) | `braces` | 3.0.3 → ? | no fix PR yet — `npm update braces --package-lock-only` | | CVE-2026-92708 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-mcm9-63f2-9j32 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-r9w8-h9r3-54w4 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-x5rw-q4pp-hg5g (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | CVE-2026-85393 (HIGH) | `node-forge` | 1.4.0 → ? | no fix PR yet — `npm update node-forge --package-lock-only` | | CVE-2026-104846 (CRITICAL) | `seroval` | 1.5.6 → 1.6.2 | no fix PR yet — `npm update seroval --package-lock-only` | | CVE-2026-104845 (HIGH) | `seroval` | 1.5.6 → 1.6.3 | no fix PR yet — `npm update seroval --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-102828 (CRITICAL) | `simple-git` | 3.36.0 → 4.0.1 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-102826 (HIGH) | `simple-git` | 3.36.0 → 4.0.0 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-102827 (HIGH) | `simple-git` | 3.36.0 → 4.0.0 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-93749 (HIGH) | `source-map-js` | 1.2.1 → 1.2.2 | no fix PR yet — `npm update source-map-js --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
ai-review-bot left a comment

AI review · advisory

Verdict: 3 things worth fixing (1 high · 2 medium) — 4 confirmed, near-duplicates merged.

⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B (no review: Laguna S 2.1) — 5 distinct, 4 confirmed, 1 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 2 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • Muse Glimmer 30B (2 findings, confidence 0.78 · thought 2.0k + wrote 686 of 32.8k tokens · 35 s): The katex bump updates the direct dependency but leaves transitive copies of katex 0.16.47 in mermaid/rehype-katex/micromark-extension-math and raises the Node engine requirement via commander 15; the
  • Gemma 4 31B (1 finding, confidence 1.0 · thought 4.6k + wrote 374 of 16.0k tokens · 118 s): The PR attempts to fix a security vulnerability by updating katex to ^0.18.0, but the change is incomplete as several transitive dependencies (mermaid, rehype-katex, micromark-extension-math
  • Mistral Medium 3.5 128B (2 findings, confidence 0.95 · wrote 563 of 16.0k tokens · 45 s): Security update needs alignment: katex@0.18.x requires Node 22.12.0+ and introduces version duplication with mermaid/rehype-katex/micromark-extension-math para-deps. Requires overrides to dedup.
  • Laguna S 2.1 — no review: answered with no usable findings object (wrote ~55.1k of 65.5k tokens (estimated: usage not reported) · 715 s over 2 attempts); it still cross-examined in round 2.

Round 2 — cross-examination

  • Muse Glimmer 30B#1 Transitive katex remains on vulnerable 0.16.47 via mermaid/rehype-katex · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3
  • Gemma 4 31B#1 Incomplete security update (transitive dependency duplication) · confirmed: Muse Glimmer 30B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3
  • Muse Glimmer 30B#2 commander 15 bumps Node engine requirement to >=22.12.0 · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3
  • Mistral Medium 3.5 128B#2 Commander version conflict in lockfile due to katex upgrade · confirmed: Laguna S 2.1 · refuted: Gemma 4 31B · support 1
  • Mistral Medium 3.5 128B#1 Security update of katex may introduce compatibility breakage with downstream co · confirmed: Gemma 4 31B, Laguna S 2.1 · refuted: — · support 2

Not posted (support < 2, or contested at a severity where one refutation vetoes)

  • Mistral Medium 3.5 128B#2 Commander version conflict in lockfile due to katex upgrade (support 1)

Synthesis — Laguna S 2.1 wrote the final review from 4 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20261006053339-2ce38c — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20261006053339-2ce38c.

### AI review · advisory <!-- tti-rv:rv-20261006053339-2ce38c: --> **Verdict: 3 things worth fixing** (1 high · 2 medium) — 4 confirmed, near-duplicates merged. <sub>⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B (no review: Laguna S 2.1) — 5 distinct, 4 confirmed, 1 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 2 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **Muse Glimmer 30B** (2 findings, confidence 0.78 · thought 2.0k + wrote 686 of 32.8k tokens · 35 s): The katex bump updates the direct dependency but leaves transitive copies of katex 0.16.47 in mermaid/rehype-katex/micromark-extension-math and raises the Node engine requirement via commander 15; the - **Gemma 4 31B** (1 finding, confidence 1.0 · thought 4.6k + wrote 374 of 16.0k tokens · 118 s): The PR attempts to fix a security vulnerability by updating `katex` to `^0.18.0`, but the change is incomplete as several transitive dependencies (`mermaid`, `rehype-katex`, `micromark-extension-math` - **Mistral Medium 3.5 128B** (2 findings, confidence 0.95 · wrote 563 of 16.0k tokens · 45 s): Security update needs alignment: katex@0.18.x requires Node 22.12.0+ and introduces version duplication with mermaid/rehype-katex/micromark-extension-math para-deps. Requires overrides to dedup. - **Laguna S 2.1** — no review: answered with no usable findings object (wrote ~55.1k of 65.5k tokens (estimated: usage not reported) · 715 s over 2 attempts); it still cross-examined in round 2. **Round 2 — cross-examination** - `Muse Glimmer 30B#1` Transitive katex remains on vulnerable 0.16.47 via mermaid/rehype-katex · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3 - `Gemma 4 31B#1` Incomplete security update (transitive dependency duplication) · confirmed: Muse Glimmer 30B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3 - `Muse Glimmer 30B#2` commander 15 bumps Node engine requirement to >=22.12.0 · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3 - `Mistral Medium 3.5 128B#2` Commander version conflict in lockfile due to katex upgrade · confirmed: Laguna S 2.1 · refuted: Gemma 4 31B · support 1 - `Mistral Medium 3.5 128B#1` Security update of katex may introduce compatibility breakage with downstream co · confirmed: Gemma 4 31B, Laguna S 2.1 · refuted: — · support 2 **Not posted** (support < 2, or contested at a severity where one refutation vetoes) - `Mistral Medium 3.5 128B#2` Commander version conflict in lockfile due to katex upgrade (support 1) **Synthesis** — Laguna S 2.1 wrote the final review from 4 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20261006053339-2ce38c` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20261006053339-2ce38c`.</sub>
@ -9066,3 +9066,1 @@
"version": "8.3.0",
"resolved": "https://registry.npmjs.org/commander/-/commander-8.3.0.tgz",
"integrity": "sha512-OkTL9umf+He2DZkUq8f8J9of7yL6RJKI24dVITBmNfZBmri9zYZQrKkuXiKhyfPSu8tUhnVBB1iKXevvnlR4Ww==",
"version": "15.0.0",
Member

package-lock.json:9066 · MEDIUM — commander 15 requires Node >=22.12.0
The upgrade pulled commander 15.0.0 (a CLI argument-parsing helper library), which declares engines: { "node": ">=22.12.0" }. Node 18/20 users — and any CI pipeline set to an older version — would get an install error. Note this is a side effect of the same katex upgrade, since katex 0.18 depends on a newer commander.

Fix: Confirm the project's Node version (in .nvmrc, CI workflows, and package.json engines) supports >=22.12.0 and bump them if needed; otherwise pin commander to a version compatible with the current Node range.

Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.

**`package-lock.json:9066`** · MEDIUM — commander 15 requires Node >=22.12.0 The upgrade pulled commander 15.0.0 (a CLI argument-parsing helper library), which declares `engines: { "node": ">=22.12.0" }`. Node 18/20 users — and any CI pipeline set to an older version — would get an install error. Note this is a side effect of the same katex upgrade, since katex 0.18 depends on a newer commander. > **Fix:** Confirm the project's Node version (in .nvmrc, CI workflows, and package.json `engines`) supports `>=22.12.0` and bump them if needed; otherwise pin commander to a version compatible with the current Node range. <sub>Evidence: **strong evidence** — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).<br>👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.</sub> <!-- tti-rv:rv-20261006053339-2ce38c:Muse Glimmer 30B#2 -->
@ -14888,6 +14888,31 @@
"uuid": "^11.1.0 || ^12 || ^13 || ^14.0.0"
Member

HIGH — Incomplete security update (transitive dependency duplication)

The update to katex to ^0.18.0 is incomplete; transitive dependencies mermaid, micromark-extension-math, and rehype-katex are still pinned to the vulnerable katex@0.16.47 (causing version duplication in the lockfile), which means the security vulnerability remains present in the project's dependency tree.

Fix: Add "katex": "^0.18.0" to the overrides object in package.json and regenerate the lockfile to force all transitive dependencies to use the secure version.

Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.

**HIGH** — Incomplete security update (transitive dependency duplication) The update to `katex` to `^0.18.0` is incomplete; transitive dependencies `mermaid`, `micromark-extension-math`, and `rehype-katex` are still pinned to the vulnerable `katex@0.16.47` (causing version duplication in the lockfile), which means the security vulnerability remains present in the project's dependency tree. > **Fix:** Add "katex": "^0.18.0" to the `overrides` object in `package.json` and regenerate the lockfile to force all transitive dependencies to use the secure version. <sub>Evidence: **strong evidence** — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).<br>👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.</sub> <!-- tti-rv:rv-20261006053339-2ce38c:Gemma 4 31B#1 -->
@ -14891,0 +14892,4 @@
"version": "8.3.0",
"resolved": "https://registry.npmjs.org/commander/-/commander-8.3.0.tgz",
"integrity": "sha512-OkTL9umf+He2DZkUq8f8J9of7yL6RJKI24dVITBmNfZBmri9zYZQrKkuXiKhyfPSu8tUhnVBB1iKXevvnlR4Ww==",
"license": "MIT",
Member

package-lock.json:14895 · HIGH — Vulnerable katex 0.16.47 still pulled in by mermaid and rehype-katex
The root katex was upgraded to 0.18.x, but mermaid, micromark-extension-math, and rehype-katex install their own nested copy of katex 0.16.47 (shown under node_modules/mermaid/node_modules/katex). This means the security flaw — a known vulnerability in the old KaTeX rendering library that could allow malicious LaTeX/MathML input to produce unsafe output — stays in the build even though the top-level dependency looks fixed.

Fix: Add "katex": "^0.18.0" to the overrides field in package.json and run npm install to regenerate package-lock.json so a single secure katex version is used everywhere.

Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.

**`package-lock.json:14895`** · HIGH — Vulnerable katex 0.16.47 still pulled in by mermaid and rehype-katex The root katex was upgraded to 0.18.x, but mermaid, micromark-extension-math, and rehype-katex install their own nested copy of katex 0.16.47 (shown under node_modules/mermaid/node_modules/katex). This means the security flaw — a known vulnerability in the old KaTeX rendering library that could allow malicious LaTeX/MathML input to produce unsafe output — stays in the build even though the top-level dependency looks fixed. > **Fix:** Add `"katex": "^0.18.0"` to the `overrides` field in package.json and run `npm install` to regenerate package-lock.json so a single secure katex version is used everywhere. <sub>Evidence: **strong evidence** — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).<br>👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.</sub> <!-- tti-rv:rv-20261006053339-2ce38c:Muse Glimmer 30B#1 -->
@ -99,3 +99,3 @@
"echarts-liquidfill": "^3.1.0",
"echarts-wordcloud": "^2.1.0",
"katex": "^0.16.47",
"katex": "^0.18.0",
Member

package.json:101 · MEDIUM — Risk of version duplication and conflicts from the katex upgrade
Upgrading katex to 0.18.x also updates its own commander dependency to 15.x (Node 22.12.0+), but rehype-katex and micromark-extension-math still use an older katex (0.16.47 with commander 8.x). Having two versions of both katex and commander can cause unexpected runtime behavior, larger packages, and potential crashes on Node versions below 22.12.0.

Fix: Add an overrides entry in package.json forcing "katex": "^0.18.0", "rehype-katex": "<latest-compatible>", "micromark-extension-math": "<latest-compatible>", and "commander": "^15.0.0" to ensure a single consistent version across the dependency tree; then regenerate the lockfile.

Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 3/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.

**`package.json:101`** · MEDIUM — Risk of version duplication and conflicts from the katex upgrade Upgrading katex to 0.18.x also updates its own commander dependency to 15.x (Node 22.12.0+), but rehype-katex and micromark-extension-math still use an older katex (0.16.47 with commander 8.x). Having two versions of both katex and commander can cause unexpected runtime behavior, larger packages, and potential crashes on Node versions below 22.12.0. > **Fix:** Add an `overrides` entry in package.json forcing `"katex": "^0.18.0"`, `"rehype-katex": "<latest-compatible>"`, `"micromark-extension-math": "<latest-compatible>"`, and `"commander": "^15.0.0"` to ensure a single consistent version across the dependency tree; then regenerate the lockfile. <sub>Evidence: **strong evidence** — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 3/4).<br>👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.</sub> <!-- tti-rv:rv-20261006053339-2ce38c:Mistral Medium 3.5 128B#1 -->
Some checks failed
baseline-security / baseline (push) Failing after 1m56s
scan / trivy-fs (push) Failing after 1m29s
ai-review / review (pull_request) Successful in 1m27s
baseline-security / baseline (pull_request) Failing after 1m59s
Required
Details
scan / trivy-fs (pull_request) Failing after 1m13s
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-katex-vulnerability:renovate/npm-katex-vulnerability
git switch renovate/npm-katex-vulnerability
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!68
No description provided.