AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-103923.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSLOW / 2.1CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAwaiting AnalysisModified Oct 05, 2026

Disclosure summary

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. From 0.11.0 until 0.18.2, KaTeX uses ordinary JavaScript property access for the renderer options object, the trust setting, default and processor setting metadata, and namespace lookup and group restoration, allowing inherited properties to be treated as explicitly supplied values. When Object.prototype is already polluted or an attacker controls the options object's prototype, attacker-controlled mathematical expressions can use an inherited trust value to enable trusted rendering and produce links capable of user-interaction cross-site scripting or loading attacker-selected external resources in a consuming application that inserts unsanitized KaTeX output into a page. KaTeX does not itself create the prototype pollution, and rendering an expression alone does not execute script. This issue is fixed in version 0.18.2.

Source-reported weakness categories

CWE-807

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-103923

Open original source · Updated Oct 05, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-238p-pmpm-9mq7

Open original source · Updated Oct 05, 2026

KaTeX: Existing prototype pollution can bypass trust restrictions

Source severity: LOW / 2.1

EcosystemPackageAffected rangeFirst patched
npmkatex>= 0.11.0, < 0.18.20.18.2

Original records & references

PUBLISHED 2026-10-01T14:17:13-04:00
MODIFIED 2026-10-05T22:17:02-04:00
INGESTED 2026-10-06T11:45:14-04:00