Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
Mermaid radar diagrams are vulnerable to DoS Moderate
CVE-2026-71439 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Mermaid Architecture diagrams are vulnerable to prototype pollution Moderate
CVE-2026-71437 was published for mermaid (npm) Aug 6, 2026
ThomasRinsma Credited to ThomasRinsma, jkim-notion, and aloisklink jkim-notion jkim-notion
aloisklink aloisklink
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
Mermaid: Improper sanitization of configuration leads to CSS injection Moderate
CVE-2026-41159 was published for mermaid (npm) May 11, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and aloisklink KeenSecurityLab KeenSecurityLab
aloisklink aloisklink
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS Moderate
CVE-2026-41150 was published for mermaid (npm) May 11, 2026
aloisklink Credited to aloisklink and Twavesx Twavesx Twavesx
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection Moderate
CVE-2026-41149 was published for mermaid (npm) May 11, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and aloisklink KeenSecurityLab KeenSecurityLab
aloisklink aloisklink
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection Moderate
CVE-2026-41148 was published for mermaid (npm) May 11, 2026
matejsmycka Credited to matejsmycka and aloisklink aloisklink aloisklink
Mermaid improperly sanitizes sequence diagram labels leading to XSS Moderate
CVE-2025-54881 was published for mermaid (npm) Aug 19, 2025
fourcube Credited to fourcube, sidharthv96, dav1tj, aloisklink, and MermaidChart sidharthv96 sidharthv96
dav1tj dav1tj aloisklink aloisklink MermaidChart MermaidChart
Mermaid does not properly sanitize architecture diagram iconText leading to XSS Moderate
CVE-2025-54880 was published for mermaid (npm) Aug 19, 2025
fourcube Credited to fourcube, sidharthv96, dav1tj, aloisklink, and MermaidChart sidharthv96 sidharthv96
dav1tj dav1tj aloisklink aloisklink MermaidChart MermaidChart
ProTip! Advisories are also available from the GraphQL API