Skip to content

Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection

Moderate severity GitHub Reviewed Published May 11, 2026 in mermaid-js/mermaid • Updated May 11, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts