OsVault/npm/mermaid
npm

mermaid

15 known vulnerabilities · 0 critical · 1 high

CVE-2025-54881

Mermaid improperly sanitizes sequence diagram labels leading to XSS

Published Aug 19, 2025
CVE-2021-35513MEDIUM

Cross-site Scripting in Mermaid

Published Dec 10, 2021
CVE-2025-54880

Mermaid does not properly sanitize architecture diagram iconText leading to XSS

Published Aug 19, 2025
CVE-2021-43861HIGH

Incorrect sanitisation function leads to `XSS` in mermaid

Published Jan 6, 2022
GHSA-6m6c-36f7-fhxh

Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS

Published May 11, 2026
GHSA-87f9-hvmw-gh4p

Mermaid: Improper sanitization of configuration leads to CSS injection

Published May 11, 2026
GHSA-xcj9-5m2h-648r

Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection

Published May 11, 2026
CVE-2022-31108MEDIUM

Possible inject arbitrary `CSS` into the generated graph affecting the container HTML

Published Jul 5, 2022
GHSA-ghcm-xqfw-q4vr

Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection

Published May 11, 2026
CVE-2026-32308

OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")

Published Mar 13, 2026
CVE-2026-26226

beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS)

Published Feb 13, 2026
CVE-2022-36036LOW

Improper Control of Generation of Code ('Code Injection') in mdx-mermaid

Published Aug 31, 2022
GHSA-39h7-pwv7-rc3x

Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)

Published Apr 24, 2026
MAL-2026-5539

Malicious code in mermaid-v11 (npm)

Published Jun 11, 2026
MAL-2026-4147

Malicious code in mcp-mermaid (npm)

Published May 19, 2026
Check your entire dependency tree at onceRun dependency scan →