Description
Versions of mermaid prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input such as A["<img src=invalid onerror=alert('XSS')></img>"] is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.2.3
- Patched version(s): 8.2.3
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in mermaid - mermaid and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- Cross-Site Scripting Vulnerability in @joeattardi/emoji-button - CVE-2021-43785
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes - CVE-2024-29203


