fix(deps): update dependency katex to ^0.18.0 [security] #68
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!68
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/npm-katex-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
^0.16.47→^0.18.0KaTeX: Existing prototype pollution can bypass trust restrictions
CVE-2026-103923 / GHSA-238p-pmpm-9mq7
More information
Details
Impact
KaTeX can act as a read-side prototype pollution gadget in applications where
Object.prototypehas already been polluted, or where an attacker can influence the prototype of the renderer options object. (KaTeX does not enable said prototype pollution. This advisory applies when combining KaTeX with other vulnerable software that allows for prototype pollution.)Affected versions may treat inherited properties from
Object.prototypeas renderer options, internal setting metadata, or namespace entries. In particular, an inheritedtrustvalue will be treated as though the application explicitly enabled trusted rendering, rather than using the documented default offalse.With attacker-controlled mathematical expressions, this can produce links capable of user-interaction cross-site scripting or load attacker-selected external resources. Exploitation requires the consuming application to insert KaTeX output into a web page without a separate sanitizer. (KaTeX does not execute scripts merely by rendering an expression.)
Other inherited settings can alter rendering behavior or resource limits. Inherited setting metadata can affect how defaults and supplied options are processed, while inherited namespace properties can be mistaken for defined macros or other internal values.
Patches
Upgrade to KaTeX v0.18.2 to remove this vulnerability.
Workarounds
delete Object.prototype.trust,delete Object.prototype.default, anddelete Object.prototype.processorbefore calling KaTeXDetails
KaTeX previously used ordinary JavaScript property access in the following contexts:
defaultandprocessorsetting metadata could be inherited fromObject.prototype.The fix adds own-property checks to each of these paths. Inherited properties are no longer accepted as renderer settings, setting metadata, namespace definitions, or values to be restored after a group ends.
For more information
If you have any questions or comments about this advisory:
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@nuxtjs/mdc@simple-git/argv-parsernpm update argv-parser --package-lock-only@vue/server-renderernpm update server-renderer --package-lock-onlybrace-expansionbrace-expansionbracesnpm update braces --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlynode-forgenpm update node-forge --package-lock-onlyserovalnpm update seroval --package-lock-onlyserovalnpm update seroval --package-lock-onlysharpnpm update sharp --package-lock-onlysimple-gitnpm update simple-git --package-lock-onlysimple-gitnpm update simple-git --package-lock-onlysimple-gitnpm update simple-git --package-lock-onlysource-map-jsnpm update source-map-js --package-lock-onlysvgonpm update svgo --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
AI review · advisory
Verdict: 3 things worth fixing (1 high · 2 medium) — 4 confirmed, near-duplicates merged.
⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B (no review: Laguna S 2.1) — 5 distinct, 4 confirmed, 1 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks
Panel debate — how this review was reached
Grounding — context: 2 files under review · 90 codebase · 6 standards chunks
Round 1 — independent reviews
katexto^0.18.0, but the change is incomplete as several transitive dependencies (mermaid,rehype-katex,micromark-extension-mathRound 2 — cross-examination
Muse Glimmer 30B#1Transitive katex remains on vulnerable 0.16.47 via mermaid/rehype-katex · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3Gemma 4 31B#1Incomplete security update (transitive dependency duplication) · confirmed: Muse Glimmer 30B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3Muse Glimmer 30B#2commander 15 bumps Node engine requirement to >=22.12.0 · confirmed: Gemma 4 31B, Mistral Medium 3.5 128B, Laguna S 2.1 · refuted: — · support 3Mistral Medium 3.5 128B#2Commander version conflict in lockfile due to katex upgrade · confirmed: Laguna S 2.1 · refuted: Gemma 4 31B · support 1Mistral Medium 3.5 128B#1Security update of katex may introduce compatibility breakage with downstream co · confirmed: Gemma 4 31B, Laguna S 2.1 · refuted: — · support 2Not posted (support < 2, or contested at a severity where one refutation vetoes)
Mistral Medium 3.5 128B#2Commander version conflict in lockfile due to katex upgrade (support 1)Synthesis — Laguna S 2.1 wrote the final review from 4 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.
Transcript
rv-20261006053339-2ce38c— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript
rv-20261006053339-2ce38c.@ -9066,3 +9066,1 @@"version": "8.3.0","resolved": "https://registry.npmjs.org/commander/-/commander-8.3.0.tgz","integrity": "sha512-OkTL9umf+He2DZkUq8f8J9of7yL6RJKI24dVITBmNfZBmri9zYZQrKkuXiKhyfPSu8tUhnVBB1iKXevvnlR4Ww==","version": "15.0.0",package-lock.json:9066· MEDIUM — commander 15 requires Node >=22.12.0The upgrade pulled commander 15.0.0 (a CLI argument-parsing helper library), which declares
engines: { "node": ">=22.12.0" }. Node 18/20 users — and any CI pipeline set to an older version — would get an install error. Note this is a side effect of the same katex upgrade, since katex 0.18 depends on a newer commander.Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.
@ -14888,6 +14888,31 @@"uuid": "^11.1.0 || ^12 || ^13 || ^14.0.0"HIGH — Incomplete security update (transitive dependency duplication)
The update to
katexto^0.18.0is incomplete; transitive dependenciesmermaid,micromark-extension-math, andrehype-katexare still pinned to the vulnerablekatex@0.16.47(causing version duplication in the lockfile), which means the security vulnerability remains present in the project's dependency tree.Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.
@ -14891,0 +14892,4 @@"version": "8.3.0","resolved": "https://registry.npmjs.org/commander/-/commander-8.3.0.tgz","integrity": "sha512-OkTL9umf+He2DZkUq8f8J9of7yL6RJKI24dVITBmNfZBmri9zYZQrKkuXiKhyfPSu8tUhnVBB1iKXevvnlR4Ww==","license": "MIT",package-lock.json:14895· HIGH — Vulnerable katex 0.16.47 still pulled in by mermaid and rehype-katexThe root katex was upgraded to 0.18.x, but mermaid, micromark-extension-math, and rehype-katex install their own nested copy of katex 0.16.47 (shown under node_modules/mermaid/node_modules/katex). This means the security flaw — a known vulnerability in the old KaTeX rendering library that could allow malicious LaTeX/MathML input to produce unsafe output — stays in the build even though the top-level dependency looks fixed.
Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 4/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.
@ -99,3 +99,3 @@"echarts-liquidfill": "^3.1.0","echarts-wordcloud": "^2.1.0","katex": "^0.16.47","katex": "^0.18.0",package.json:101· MEDIUM — Risk of version duplication and conflicts from the katex upgradeUpgrading katex to 0.18.x also updates its own commander dependency to 15.x (Node 22.12.0+), but rehype-katex and micromark-extension-math still use an older katex (0.16.47 with commander 8.x). Having two versions of both katex and commander can cause unexpected runtime behavior, larger packages, and potential crashes on Node versions below 22.12.0.
Evidence: strong evidence — two or more reviewers, quote verified against the diff, anchored on a changed line (panel 3/4).
👍 if this was worth flagging · 👎 if it was not — a reaction on this comment is the whole feedback loop.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.