mermaid-js Mermaid是mermaid-js社区开源的一款通过文本定义图表的图表绘制工具。 mermaid-js mermaid 11.6.0版本至11.16.1之前版本存在安全漏洞,该漏洞源于对ticks参数验证不当,允许任意大值,可能导致高CPU使用率并冻结渲染网页或JavaScript进程,甚至因内存耗尽而终止进程。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mermaid-js | mermaid | >= 11.6.0, < 11.16.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mermaid-js | mermaid | >= 11.6.0, < 11.16.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71437 | 6.5 MEDIUM | Mermaid Architecture diagrams are vulnerable to prototype pollution |
| CVE-2026-71436 | 5.3 MEDIUM | Mermaid XY Charts are vulnerable to an infinite loop DoS |
| CVE-2026-50159 | 5.3 MEDIUM | Mermaid allows CSS injection applying to sibling elements of the diagram |
| CVE-2026-71438 | 2.4 LOW | Mermaid configuration APIs allow prototype pollution |
No comments yet