logo

Database

Reflected cross-site scripting (XSS) In mermaid

Description

Incorrect sanitisation function leads to XSS in mermaid

Impact

Malicious diagrams can contain javascript code that can be run at diagram readers machines.

Patches

The users should upgrade to version 8.13.8

Workarounds

You need to upgrade in order to avoid this issue.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-BH6W9 – Vulnerability | Fluid Attacks Database