Vulnerabilities/

Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS

Severity:
Medium

Description

Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates.

Recommendation

Update the mermaid package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mermaid
Anything's wrong? Let us know Last updated on May 11, 2026