GHSA-rhh3-jpg6-66xh
Mermaid radar diagrams are vulnerable to DoS
Quick fix
GHSA-rhh3-jpg6-66xh — mermaid: upgrade to the fixed version with the command below.
npm install mermaid@11.16.1 Details
### Impact
Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.
#### Proof-of-concept
```txt radar-beta axis a, b curve c {1, 1} ticks 1000000000 ```
### Patches
_Has the problem been patched? What versions should users upgrade to?_
This problem has been patched by https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e, which was released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1)
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
There are no known workarounds without updating to a patched version of mermaid.
### References
_Are there any links users can visit to find out more?_
- https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh [WEB]
- https://github.com/mermaid-js/mermaid/pull/8022 [WEB]
- https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e [WEB]
- https://github.com/mermaid-js/mermaid [PACKAGE]
- https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 [WEB]