Description
Malicious diagrams can contain javascript code that can be run at diagram readers machines.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.13.8
- Patched version(s): 8.13.8
References
Related Issues
- jquery.terminal self XSS on user input - CVE-2021-43862
- Reflected XSS from the callback handler's error query parameter - CVE-2021-32702
- Reflected XSS when using flashMessages or languageDictionary - CVE-2021-32641
- Cross-site Scripting in Mermaid - CVE-2021-35513
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on February 03, 2023