VDB
Sign up
HIGH

GHSA-w32g-5hqp-gg6q

Cross-Site Scripting in mermaid

Quick fix

GHSA-w32g-5hqp-gg6q — mermaid: upgrade to the fixed version with the command below.

npm install mermaid@8.2.3

Details

Versions of `mermaid` prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input such as `A["<img src=invalid onerror=alert('XSS')></img>"] ` is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.

## Recommendation

Upgrade to version 8.2.3 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mermaid
Introduced in: 0Fixed in: 8.2.3
Fixnpm install mermaid@8.2.3

References