Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/mermaid-js/mermaid

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Mermaid versions from 11.6.0 up to but not including 11.16.1 contain a vulnerability where the Radar Diagrams feature accepts arbitrarily large values for the ticks parameter. This unchecked input can cause excessive CPU usage and potentially freeze the rendering webpage or JavaScript process until it is terminated due to resource exhaustion. The issue is resolved in version 11.16.1.

Join the discussion

A prototype pollution vulnerability exists in mermaid-js mermaid prior to versions 10.9.8 and 11.16.1. The issue arises from the way configuration setters merge user-supplied configuration into internal config using a deep-merge helper, which can be exploited if untrusted data is passed directly to these setters. This misuse is outside documented usage, and diagram-supplied configuration is not affected. The vulnerability has a low severity score and is fixed in versions 10.9.8 and 11.16.1.

Join the discussion

Mermaid versions prior to 10.9.8 and 11.16.1 are vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. This allows an attacker who can supply diagram text to inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. The vulnerability is fixed in versions 10.9.8 and 11.16.1.

Join the discussion

Mermaid versions from 11.5.0 up to but not including 11.16.1 are vulnerable to prototype pollution via the Architecture Diagrams feature. This occurs when a diagram defines a group with an id of __proto__, which is used directly as an object property key without validation. An attacker able to supply diagram text can exploit this to modify Object.prototype, potentially altering the behavior of the embedding application. The vulnerability is fixed in version 11.16.1.

Join the discussion

Mermaid-js versions from 10.6.0 up to but not including 10.9.8, and version 11.16.0, contain a vulnerability in the XY Charts feature where an infinite loop can occur in the setXAxisRangeData function when invalid parameters are used. This infinite loop can lead to a denial of service by causing a RangeError or crashing the JavaScript process due to memory exhaustion. The issue is resolved in versions 10.9.8 and 11.16.1.

Join the discussion

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates.mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.

Join the discussion

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @counter-style) are also injectable as stylis hoists them to top level. This allows page defacement and DOM attribute exfiltration via CSS :has() selectors. This vulnerability is fixed in 10.9.6 and 11.15.0.

Join the discussion

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed <iframe>.

Join the discussion

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through addStyleClass() into createCssStyles() and is assigned to style.innerHTML, so a closing brace (}) in the value terminates the generated CSS selector and turns everything after it into a new CSS rule on the page. This enables page defacement, user tracking via url() callbacks, and DOM attribute exfiltration. This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting "securityLevel": "sandbox", which prevents the issue by rendering the mermaid diagram in a sandboxed <iframe>.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:npm/mermaid-js/mermaid
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses