Description
Malicious diagrams can contain javascript code that can be run at diagram readers machines.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.13.8
- Patched version(s): 8.13.8
References
Related Issues
- XSS in apexcharts - CVE-2021-23327
- dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration - CVE-2026-34725
- XSS in `*Text` options of the Datepicker widget in jquery-ui - CVE-2021-41183
- cumulative-distribution-function Infinite Loop vulnerability - CVE-2021-29486
You might also like:
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on February 03, 2023


