KaTeX 0.18.7 appears to be a healthy, mature, and actively maintained dependency. It has a long release history with 122 releases, 34 releases in the last 12 months, a recent release, active repository work, eight active contributors, organization backing, tests, documentation, a changelog in the repository, security tooling, and a security policy. The main reservations are the absence of build provenance attestation, incomplete explicit GitHub Actions token-permission declarations, one pull-request-target workflow, and an install-time prepare script; these are transparency and workflow-hygiene concerns rather than evidence of abandonment. The package is suitable to depend on, subject to normal review of its build and install behavior.
94%
Total Score
100
100
100
70
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-293837 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. katex is vulnerable to Prototype Pollution in versions 0.11.0 - 0.18.1. | 0.11.0 - 0.18.1 | Medium |
CVE-2025-23207 katex is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.12.0 - 0.16.20. | 0.12.0 - 0.16.20 | Medium |
CVE-2024-28246 katex is vulnerable to Incomplete List of Disallowed Inputs in versions 0.11.0 - 0.16.10. | 0.11.0 - 0.16.10 | Medium |
CVE-2024-28245 katex is vulnerable to Improper Encoding or Escaping of Output in versions 0.11.0 - 0.16.10. | 0.11.0 - 0.16.10 | Medium |
CVE-2024-28244 katex is vulnerable to Unchecked Input for Loop Condition in versions 0.15.4 - 0.16.10. | 0.15.4 - 0.16.10 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
commander Version ^15.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.