Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rhh3-jpg6-66xh
  • npm/mermaid
Mermaid radar diagrams are vulnerable to DoS 06 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-c4c3-pg64-4m4v
  • npm/mermaid
Mermaid configuration APIs allow prototype pollution 06 Aug
  • Fix available
  • Severity - 2.4 (Low)
GHSA-6x64-9x62-f2gx
  • npm/mermaid
Mermaid allows CSS injection applying to sibling elements of the diagram 06 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-3rrr-jr9j-h3q3
  • npm/mermaid
Mermaid Architecture diagrams are vulnerable to prototype pollution 06 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2v8p-3f2j-5mp7
  • npm/mermaid
Mermaid XY Charts are vulnerable to an infinite loop DoS 06 Aug
  • Fix available
  • Severity - 5.3 (Medium)
MAL-2026-5539
  • npm/mermaid-v11
Malicious code in mermaid-v11 (npm) 11 Jun
  • No fix available
MAL-2026-4147
  • npm/mcp-mermaid
Malicious code in mcp-mermaid (npm) 19 May
  • No fix available
GHSA-87f9-hvmw-gh4p
  • npm/mermaid
Mermaid: Improper sanitization of configuration leads to CSS injection 11 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-6m6c-36f7-fhxh
  • npm/mermaid
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS 11 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-ghcm-xqfw-q4vr
  • npm/mermaid
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection 11 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-xcj9-5m2h-648r
  • npm/mermaid
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection 11 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-39h7-pwv7-rc3x
  • npm/@excalidraw/excalidraw
  • npm/@excalidraw/mermaid-to-excalidraw
Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering) 24 Apr
  • Fix available
GHSA-cgmm-x5ww-q5cr
  • npm/beautiful-mermaid
beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) 13 Feb
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7rqq-prvp-x9jh
  • npm/mermaid
Mermaid improperly sanitizes sequence diagram labels leading to XSS 19 Aug 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-8gwm-58g9-j8pw
  • npm/mermaid
Mermaid does not properly sanitize architecture diagram iconText leading to XSS 19 Aug 2025
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-m4gq-x24j-jpmf
  • npm/mermaid
Prototype pollution vulnerability found in Mermaid's bundled version of DOMPurify 22 Oct 2024
  • Fix available
  • Severity - 7.0 (High)