The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
{ "binaries": [ { "binary_version": "8.13.8+~cs10.4.16-1", "binary_name": "node-mermaid" } ] }