Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

mermaid-js — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting mermaid-js. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Mermaid-js is a JavaScript-based diagramming and charting tool that enables developers to create visualizations through text-based descriptions. Historically, it has been susceptible to cross-site scripting (XSS) vulnerabilities due to improper input sanitization in rendering functions, with several instances allowing remote code execution through malicious diagram definitions. The project has addressed multiple security flaws, including those enabling arbitrary code execution via crafted diagram syntax, though no major public security incidents have been documented. Despite these vulnerabilities, the tool remains widely adopted for documentation and visualization purposes, with ongoing efforts to improve security through input validation and sandboxed rendering environments.

Top products by mermaid-js: mermaid zenuml-core
CVE ID Title CVSS Severity Published
CVE-2026-71439 Mermaid radar diagrams are vulnerable to DoS — mermaid CWE-606 5.3 Medium 2026-08-06
CVE-2026-71438 Mermaid configuration APIs allow prototype pollution — mermaid CWE-1321 2.4 Low 2026-08-06
CVE-2026-50159 Mermaid allows CSS injection applying to sibling elements of the diagram — mermaid CWE-94 5.3 Medium 2026-08-06
CVE-2026-71437 Mermaid Architecture diagrams are vulnerable to prototype pollution — mermaid CWE-1321 6.5 Medium 2026-08-06
CVE-2026-71436 Mermaid XY Charts are vulnerable to an infinite loop DoS — mermaid CWE-835 5.3 Medium 2026-08-06
CVE-2026-41150 Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS — mermaid CWE-835 - - 2026-05-29
CVE-2026-41159 Mermaid: Improper sanitization of configuration leads to CSS injection — mermaid CWE-94 - - 2026-05-29
CVE-2026-41149 Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection — mermaid CWE-94 - - 2026-05-22
CVE-2026-41148 Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection — mermaid CWE-94 - - 2026-05-22
CVE-2025-54881 Mermaid improperly sanitizes of sequence diagram labels leading to XSS — mermaid CWE-79 5.4AI Medium AI 2025-08-19
CVE-2025-54880 Mermaid does not properly sanitize architecture diagram iconText leading to XSS — mermaid CWE-79 5.4AI Medium AI 2025-08-19
CVE-2024-38527 Cross-site Scripting in ZenUML — zenuml-core CWE-79 5.4 Medium 2024-06-26
CVE-2022-31108 Arbitrary `CSS` injection into the generated graph affecting the container HTML in mermaid.js — mermaid CWE-74 4.1 Medium 2022-06-28
CVE-2021-43861 Incorrect sanitisation function leads to `XSS` — mermaid CWE-79 7.2 High 2021-12-30

This page lists every published CVE security advisory associated with mermaid-js. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.