Mermaid before 8.11.0 allows XSS when the antiscript feature is used.
{ "binaries": [ { "binary_version": "8.13.8+~cs10.4.16-1", "binary_name": "node-mermaid" } ] }