Description
Rendering an untrusted architecture-beta diagram lets the diagram author write an arbitrary property with the value horizontal or vertical onto Object.prototype. A group id of __proto__ is accepted as a valid parent.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): >= 11.5.0, < 11.16.1
- Patched version(s): 11.16.1
References
Could your website be exposed too?
SmartScanner can check your website for Mermaid Architecture diagrams are vulnerable to prototype pollution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Mermaid radar diagrams are vulnerable to DoS - CVE-2026-71439
- CASL Ability is Vulnerable to Prototype Pollution - CVE-2026-1774
- Immutable is vulnerable to Prototype Pollution - CVE-2026-29063
- deepHas vulnerable to Prototype Pollution via constructor.prototype - CVE-2026-25047


