Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

Cross-Site Scripting in mermaid

GHSA-w32g-5hqp-gg6q

Published ยท Modified

Description

Versions of mermaid prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input such as A["<img src=invalid onerror=alert('XSS')></img>"] is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.

Recommendation

Upgrade to version 8.2.3 or later

Ready to move

Start Securing

Free, no credit card | First findings in minutes