Description
beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams.
Recommendation
Update the beautiful-mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.3
- Patched version(s): 0.1.3
References
Could your website be exposed too?
SmartScanner can check your website for beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution - CVE-2026-42045
- TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection - CVE-2026-47761


