Vulnerabilities/

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

Severity:
High

Description

The Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in Mermaid diagrams, enabling XSS through Mermaid’s click directive which can execute arbitrary JavaScript.

Recommendation

Update the oneuptime package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
oneuptime
Anything's wrong? Let us know Last updated on March 16, 2026