Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-71438— Mermaid configuration APIs allow prototype pollution

CVSS 2.4 · Low EPSS 0.17% · P6

Affected Version Matrix 2

VendorProductVersion RangeStatus
mermaid-jsmermaid< 10.9.8affected
>= 11.0.0-alpha.1, < 11.16.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-71438

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mermaid configuration APIs allow prototype pollution
Source: CVE Program / CVE List V5
Vulnerability Description
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration into Mermaid's internal config using the assignWithDepth deep-merge helper, which is vulnerable to prototype pollution. This is only exploitable if an application forwards untrusted data directly into one of these configuration entry points, which is outside their documented usage; diagram-supplied configuration (e.g. %%{init: {}}%% or YAML frontmatter) is not affected. This issue is fixed in versions 10.9.8 and 11.16.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5
Vulnerability Title
mermaid-js mermaid 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
mermaid-js Mermaid是mermaid-js社区开源的一款通过文本定义图表的图表绘制工具。 mermaid-js mermaid 10.9.8之前版本和11.16.1之前版本存在输入验证错误漏洞,该漏洞源于配置setters使用assignWithDepth深度合并时容易受到原型污染攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
mermaid-jsmermaid < 10.9.8 -

II. Public POCs for CVE-2026-71438

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71438

登录查看更多情报信息。

Patches & Fixes for CVE-2026-71438 (1)

Vendor Advisories for CVE-2026-71438 (1)

Vendor Pages for CVE-2026-71438 (1)

Other References for CVE-2026-71438 (1)

Same Patch Batch · mermaid-js · 2026-08-06 · 5 CVEs total

CVE-2026-714376.5 MEDIUMMermaid Architecture diagrams are vulnerable to prototype pollution
CVE-2026-714395.3 MEDIUMMermaid radar diagrams are vulnerable to DoS
CVE-2026-714365.3 MEDIUMMermaid XY Charts are vulnerable to an infinite loop DoS
CVE-2026-501595.3 MEDIUMMermaid allows CSS injection applying to sibling elements of the diagram

IV. Related Vulnerabilities

V. Comments for CVE-2026-71438

No comments yet


Leave a comment