Skip to main content

CVE-2025-54881: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in mermaid-js mermaid

Medium
VulnerabilityCVE-2025-54881cvecve-2025-54881cwe-79
Published: Tue Aug 19 2025 (08/19/2025, 17:04:29 UTC)
Source: CVE Database V5
Vendor/Project: mermaid-js
Product: mermaid

Description

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-07-31T17:23:33.475Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68a4b1bfad5a09ad00f9671f

Added to database: 8/19/2025, 5:17:51 PM

Last updated: 8/19/2025, 5:17:51 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats