<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:04:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-4473</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-4473</link>
      <description>EUVD-2026-4473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-4473</guid>
    </item>
    <item>
      <title>fkie_cve-2024-28246</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-28246</link>
      <description>&lt;p&gt;KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`. Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`. Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-28246</guid>
    </item>
    <item>
      <title>GHSA-3wc5-fcw2-2329 — KaTeX missing normalization of the protocol in URLs allows bypassing forbidden protocols</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3wc5-fcw2-2329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: katex&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;### Workarounds
* Allow-list instead of block protocols in your `trust` function.
* Manually lowercase `context.protocol` via `context.protocol.toLowerCase()` before attempting to check for certain protocols.
* Avoid use of or turn off the `trust` option.&lt;/p&gt;
&lt;p&gt;### Details
KaTeX did not normalize the `protocol` entry of the `context` object provided to a user-specified `trust`-function, so it could be a mix of lowercase and/or uppercase letters.&lt;/p&gt;
&lt;p&gt;It is generally better to allow-list by protocol, in which case this would normally not be an issue. But in some cases, you might want to block-list, and the [KaTeX documentation](https://katex.org/docs/options.html) even provides such an example:&lt;/p&gt;
&lt;p&gt;&amp;gt; Allow all commands but forbid specific protocol: `trust: (context) =&amp;gt; context.protocol !== &amp;#39;file&amp;#39;`&lt;/p&gt;
&lt;p&gt;Currently KaTeX internally sees `file:` and `File:` URLs as different protocols, so `context.protocol` can be `file` or `File`, so the above check does not suffice.  A simple workaround would be:&lt;/p&gt;
&lt;p&gt;&amp;gt;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: katex&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to block-list certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;### Workarounds
* Allow-list instead of block protocols in your `trust` function.
* Manually lowercase `context.protocol` via `context.protocol.toLowerCase()` before attempting to check for certain protocols.
* Avoid use of or turn off the `trust` option.&lt;/p&gt;
&lt;p&gt;### Details
KaTeX did not normalize the `protocol` entry of the `context` object provided to a user-specified `trust`-function, so it could be a mix of lowercase and/or uppercase letters.&lt;/p&gt;
&lt;p&gt;It is generally better to allow-list by protocol, in which case this would normally not be an issue. But in some cases, you might want to block-list, and the [KaTeX documentation](https://katex.org/docs/options.html) even provides such an example:&lt;/p&gt;
&lt;p&gt;&amp;gt; Allow all commands but forbid specific protocol: `trust: (context) =&amp;gt; context.protocol !== &amp;#39;file&amp;#39;`&lt;/p&gt;
&lt;p&gt;Currently KaTeX internally sees `file:` and `File:` URLs as different protocols, so `context.protocol` can be `file` or `File`, so the above check does not suffice.  A simple workaround would be:&lt;/p&gt;
&lt;p&gt;&amp;gt;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3wc5-fcw2-2329</guid>
    </item>
    <item>
      <title>gsd-2024-28246</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-28246</link>
      <description>gsd-2024-28246</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-28246</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-28246</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28246</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: node-katex&lt;/p&gt;
&lt;p&gt;KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`. Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: node-katex&lt;/p&gt;
&lt;p&gt;KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX&amp;#39;s `trust` option, specifically that provides a function to blacklist certain URL protocols, can be fooled by URLs in malicious inputs that use uppercase characters in the protocol. In particular, this can allow for malicious input to generate `javascript:` links in the output, even if the `trust` function tries to forbid this protocol via `trust: (context) =&amp;gt; context.protocol !== &amp;#39;javascript&amp;#39;`. Upgrade to KaTeX v0.16.10 to remove this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-28246</guid>
    </item>
  </channel>
</rss>
