Vulnerabilities/

Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)

Severity:
Medium

Description

@excalidraw/[email protected] depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could trigger XSS through Mermaid’s KaTeX label rendering path.

This is patched in @excalidraw/[email protected] by updating @excalidraw/mermaid-to-excalidraw to 2.2.2, which uses a patched Mermaid 11 release.

Recommendation

Update the @excalidraw/excalidraw package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@excalidraw/excalidraw
Anything's wrong? Let us know Last updated on April 24, 2026