Description
Malicious diagrams can contain javascript code that can be run at diagram readers machines.
Recommendation
Update the mermaid
package to the latest compatible version. Followings are version details:
- Affected version(s): < 8.13.8
- Patched version(s): 8.13.8
References
Related Issues
- Finance.js vulnerable to DoS via the seekZero() parameter - CVE-2025-56572
- Mermaid does not properly sanitize architecture diagram iconText leading to XSS - CVE-2025-54880
- jsPDF Bypass Regular Expression Denial of Service (ReDoS) - CVE-2025-29907
- Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify - Vulnerability
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on February 03, 2023