Mermaid before 8.11.0 allows XSS when the antiscript feature is used.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/mermaid-js/mermaid/issues/2122 | third party advisory |
https://github.com/mermaid-js/mermaid/pull/2123 | third party advisory patch |
https://github.com/mermaid-js/mermaid/releases/tag/8.11.0-rc2 | third party advisory release notes |