VDB
Sign up
HIGH7.2

GHSA-p3rp-vmj9-gv6v

Incorrect sanitisation function leads to `XSS` in mermaid

Quick fix

GHSA-p3rp-vmj9-gv6v — mermaid: upgrade to the fixed version with the command below.

npm install mermaid@8.13.8

Details

### Impact Malicious diagrams can contain javascript code that can be run at diagram readers machines.

### Patches The users should upgrade to version 8.13.8

### Workarounds You need to upgrade in order to avoid this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mermaid
Introduced in: 0Fixed in: 8.13.8
Fixnpm install mermaid@8.13.8

References