Description
Rendering an untrusted architecture-beta diagram lets the diagram author write an arbitrary property with the value horizontal or vertical onto Object.prototype. A group id of __proto__ is accepted as a valid parent.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): >= 11.5.0, < 11.16.1
- Patched version(s): 11.16.1
References
Related Issues
- Mermaid radar diagrams are vulnerable to DoS - CVE-2026-71439
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
- Immutable is vulnerable to Prototype Pollution - CVE-2026-29063
- deepHas vulnerable to Prototype Pollution via constructor.prototype - CVE-2026-25047
You might also like:
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on August 06, 2026


