Skip to content

Incorrect sanitisation function leads to `XSS`

High
knsv published GHSA-p3rp-vmj9-gv6v Dec 29, 2021

Package

npm mermaid (npm)

Affected versions

8.13.6

Patched versions

None

Description

Impact

Malicious diagrams can contain javascript code that can be run at diagram readers machines.

Patches

The users should upgrade to version 8.13.8

Workarounds

You need to upgrade in order to avoid this issue.

Severity

High

CVE ID

CVE-2021-43861

Weaknesses

No CWEs