Vulnerabilidades en mermaid-js
14 resultadosAnálisis Vexday
Mermaid-js apresenta 9 vulnerabilidades no registro, sendo 4 publicadas nos últimos 90 dias, sem indicadores de exploração ativa em campo. A fraqueza dominante é Cross-Site Scripting (CWE-79), padrão em bibliotecas de renderização web, e nenhuma vulnerabilidade crítica foi identificada, sugerindo risco moderado e controlável com atualizações regulares.
CVE-2021-43861HIGHIncorrect sanitisation function leads to `XSS`EPSS 0.9%CVE-2022-31108MEDIUMArbitrary `CSS` injection into the generated graph affecting the container HTML in mermaid.jsEPSS 0.9%CVE-2025-54881MEDIUMMermaid improperly sanitizes of sequence diagram labels leading to XSSEPSS 0.8%CVE-2026-50159MEDIUMMermaid allows CSS injection applying to sibling elements of the diagramEPSS 0.6%CVE-2026-41149MEDIUMMermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injectionEPSS 0.4%CVE-2026-41159MEDIUMMermaid: Improper sanitization of configuration leads to CSS injectionEPSS 0.4%CVE-2026-71439MEDIUMMermaid radar diagrams are vulnerable to DoSEPSS 0.4%CVE-2026-41150MEDIUMMermaid Gantt Charts are vulnerable to an Infinite Loop DoSEPSS 0.4%CVE-2024-38527MEDIUMCross-site Scripting in ZenUMLEPSS 0.4%CVE-2025-54880MEDIUMMermaid does not properly sanitize architecture diagram iconText leading to XSSEPSS 0.4%CVE-2026-41148MEDIUMMermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injectionEPSS 0.3%CVE-2026-71436MEDIUMMermaid XY Charts are vulnerable to an infinite loop DoSEPSS 0.3%CVE-2026-71437MEDIUMMermaid Architecture diagrams are vulnerable to prototype pollutionEPSS 0.3%CVE-2026-71438LOWMermaid configuration APIs allow prototype pollutionEPSS 0.2%