Description
Under the default configuration, Mermaid state diagram’s classDef allow DOM injection that escapes the SVG, although <script> tags are removed, preventing XSS.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
Affected version(s): **<= 10.9.5 >= 11.0.0-alpha.1, <= 11.14.0** Patched version(s): **10.9.6 11.15.0**
References
Could your website be exposed too?
SmartScanner can check your website for Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection - CVE-2026-41148
- Mermaid: Improper sanitization of configuration leads to CSS injection - CVE-2026-41159
- Flowise: Code Injection in CSVAgent leads to Authenticated RCE - CVE-2026-41137
- Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde - CVE-2026-26974


