Possible inject arbitrary `CSS` into the generated graph affecting the container HTML
- Severity:
- Medium
Description
An attacker is able to inject arbitrary CSS into the generated graph allowing them to change the styling of elements outside of the generated graph, and potentially exfiltrate sensitive information by using specially crafted CSS selectors.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): >= 8.0.0, < 9.1.2
- Patched version(s): 9.1.2
References
Related Issues
- Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality - CVE-2021-32809
- Unsanitized JavaScript code injection possible in gatsby-plugin-mdx - CVE-2022-25863
- Mermaid allows CSS injection applying to sibling elements of the diagram - CVE-2026-50159
- Improper handling of CSS at-rules in lettersanitizer - CVE-2022-31103
You might also like:
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on July 21, 2023


