Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify
- Severity:
- High
Description
The following bundled files within the Mermaid NPM package contain a bundled version of DOMPurify that is vulnerable to https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674, potentially resulting in an XSS attack.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): <= 10.9.2
- Patched version(s): 10.9.3
References
Related Issues
- Prototype Pollution in lodash.defaultsdeep - lodash.defaultsdeep - Vulnerability
- Prototype pollution vulnerability in 'libnested - CVE-2020-28283
- canvg Prototype Pollution vulnerability - CVE-2025-25977
- dset Prototype Pollution vulnerability - CVE-2024-21529
You might also like:
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on October 23, 2024


