Vulnerabilidades em mermaid-js
9 resultadosAnálise Vexday
Mermaid-js apresenta 9 vulnerabilidades no registro, sendo 4 publicadas nos últimos 90 dias, sem indicadores de exploração ativa em campo. A fraqueza dominante é Cross-Site Scripting (CWE-79), padrão em bibliotecas de renderização web, e nenhuma vulnerabilidade crítica foi identificada, sugerindo risco moderado e controlável com atualizações regulares.
CVE-2021-43861HIGHIncorrect sanitisation function leads to `XSS`EPSS 0.9%CVE-2022-31108MEDIUMArbitrary `CSS` injection into the generated graph affecting the container HTML in mermaid.jsEPSS 0.9%CVE-2025-54881MEDIUMMermaid improperly sanitizes of sequence diagram labels leading to XSSEPSS 0.8%CVE-2026-41149MEDIUMMermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injectionEPSS 0.4%CVE-2026-41159MEDIUMMermaid: Improper sanitization of configuration leads to CSS injectionEPSS 0.4%CVE-2026-41150MEDIUMMermaid Gantt Charts are vulnerable to an Infinite Loop DoSEPSS 0.4%CVE-2024-38527MEDIUMCross-site Scripting in ZenUMLEPSS 0.4%CVE-2025-54880MEDIUMMermaid does not properly sanitize architecture diagram iconText leading to XSSEPSS 0.4%CVE-2026-41148MEDIUMMermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injectionEPSS 0.3%