Vulnerabilities/

Mermaid does not properly sanitize architecture diagram iconText leading to XSS

Severity:
Medium

Description

In the default configuration of mermaid 11.9.0, user supplied input for architecture diagram icons is passed to the d3 html() method, creating a sink for cross site scripting.

Recommendation

Update the mermaid package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mermaid
Anything's wrong? Let us know Last updated on August 20, 2025

This issue is available in SmartScanner Professional

See Pricing