VDB
Sign up
MEDIUM5.3

GHSA-6m6c-36f7-fhxh

Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS

Quick fix

GHSA-6m6c-36f7-fhxh — mermaid: upgrade to the fixed version with the command below.

npm install mermaid@11.15.0

Details

### Impact

Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the [`excludes` attribute](https://mermaid.js.org/syntax/gantt.html?#excludes) to exclude all dates.

Example:

``` gantt excludes monday,tuesday,wednesday,thursday,friday,saturday,sunday DoS :2025-01-01, 1d ```

`mermaid.parse` is unaffected, unless you then call the `ganttDb.getTasks()` (which is called when rendering a diagram).

### Patches

This has been patched in:

- [v11.15.0](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0) (see [faafb5d49106dd32c367f3882505f2dd625aa30e](https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e)) - [v10.9.6](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6) (see [a59ea56174712ee5430dfd5bc877cb5151f501a6](https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6))

### Workarounds

There are no workarounds available without updating to a newer version of mermaid.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mermaid
Introduced in: 11.0.0-alpha.1Fixed in: 11.15.0
Fixnpm install mermaid@11.15.0
npm/mermaid
Introduced in: 0Fixed in: 10.9.6
Fixnpm install mermaid@10.9.6

References