Reflected cross-site scripting (XSS) In mermaid
Description
Incorrect sanitisation function leads to XSS in mermaid
Impact
Malicious diagrams can contain javascript code that can be run at diagram readers machines.
Patches
The users should upgrade to version 8.13.8
Workarounds
You need to upgrade in order to avoid this issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 8.13.8 | ||
debian 11 | 8.7.0+ds+~cs27.17.17-3+deb11u2 | ||
debian 14 | 8.13.8+~cs10.4.16-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.