Vulnerabilities/

Mermaid improperly sanitizes sequence diagram labels leading to XSS

Severity:
Medium

Description

In the default configuration of mermaid 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

Recommendation

Update the mermaid package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mermaid
Anything's wrong? Let us know Last updated on September 04, 2025

This issue is available in SmartScanner Professional

See Pricing