Package Health

katex

Fast math typesetting for the web.

Latest 0.19.0NPMNPM

88%

Total Score

healthy

Healthy: frequent releases and an active, organization-backed repository support dependable adoption.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All four workflows were analyzed successfully, with no untrusted checkout or script-injection findings. However, all 20 action references are unpinned and one low-confidence high-severity audit finding flags an unpinned container image, so workflow supply-chain hygiene is a caution.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-103923 New
katex is vulnerable to Reliance on Untrusted Inputs in a Security Decision in versions 0.11.0 - 0.18.2.
0.11.0 - 0.18.2
Low
AIKIDO-2026-293837 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
katex is vulnerable to Prototype Pollution in versions 0.11.0 - 0.18.1.
0.11.0 - 0.18.1
Medium
CVE-2025-23207
katex is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.12.0 - 0.16.20.
0.12.0 - 0.16.20
Medium
CVE-2024-28246
katex is vulnerable to Incomplete List of Disallowed Inputs in versions 0.11.0 - 0.16.10.
0.11.0 - 0.16.10
Medium
CVE-2024-28245
katex is vulnerable to Improper Encoding or Escaping of Output in versions 0.11.0 - 0.16.10.
0.11.0 - 0.16.10
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
commander
Version ^15.0.0
—
—

Weekly Downloads

Info

Last Published
10 days ago
Created
12 years ago
Unpacked Size
3.9 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform