MEDIUM 6.1 npm
Cross-site Scripting in Mermaid
GHSA-4f6x-49g2-99fm · CVE-2021-35513
Published · Modified
Description
Mermaid before 8.11.0 allows XSS when the antiscript feature is used.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-35513
- WEB https://github.com/mermaid-js/mermaid/issues/2122
- WEB https://github.com/mermaid-js/mermaid/pull/2123
- WEB https://github.com/mermaid-js/mermaid/pull/2123/commits/3d22fa5d2435de5acc18de6f88474a6e8675a60e
- WEB https://github.com/mermaid-js/mermaid/releases/tag/8.11.0-rc2
Ready to move
Start Securing
Free, no credit card | First findings in minutes