Description
@excalidraw/[email protected] depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could trigger XSS through Mermaid’s KaTeX label rendering path.
This is patched in @excalidraw/[email protected] by updating @excalidraw/mermaid-to-excalidraw to 2.2.2, which uses a patched Mermaid 11 release.
Recommendation
Update the @excalidraw/mermaid-to-excalidraw package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.3.0, < 1.1.3
- Patched version(s): 1.1.3
References
Could your website be exposed too?
SmartScanner can check your website for Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) - @excalidraw/mermaid-to-excalidraw and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) - Vulnerability
- Mermaid improperly sanitizes sequence diagram labels leading to XSS - CVE-2025-54881
- @tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Ori - Vulnerability
- OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose") - CVE-2026-32308


