PT-2026-68805 · Mermaid · Mermaid

CVE-2026-71437

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

6.5

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Mermaid versions 11.5.0 through 11.16.0
Description Mermaid Architecture Diagrams are subject to prototype pollution, a condition where an attacker can manipulate the Object.prototype of the JavaScript environment. This occurs when a diagram defines a group with an id of proto, as the group id is used as an object property key without proper validation. An attacker providing malicious diagram text can inject the values horizontal or vertical into Object.prototype. This can lead to corrupted configuration defaults, bypassed truthiness checks, denial of service, or logic corruption within the embedding application. This issue is specifically related to the architecture-beta diagram type.
Recommendations Update Mermaid to version 11.16.1.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71437
GHSA-3RRR-JR9J-H3Q3

Affected Products

Mermaid