PT-2021-23984 · Mermaid · Mermaid

·

CVE-2021-43861

·

Published

2021-12-30

·

Updated

2023-07-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mermaid versions prior to 8.13.8
Description: Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Malicious diagrams can run javascript code at diagram readers' machines.
Recommendations: For versions prior to 8.13.8, upgrade to version 8.13.8 to receive a patch. At the moment, there is no other information about additional mitigation measures aside from upgrading to the patched version.

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43861
GHSA-P3RP-VMJ9-GV6V

Affected Products

Mermaid