PT-2026-68805 · Mermaid · Mermaid
CVE-2026-71437
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v4.0
6.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Mermaid versions 11.5.0 through 11.16.0
Description
Mermaid Architecture Diagrams are subject to prototype pollution, a condition where an attacker can manipulate the
Object.prototype of the JavaScript environment. This occurs when a diagram defines a group with an id of proto, as the group id is used as an object property key without proper validation. An attacker providing malicious diagram text can inject the values horizontal or vertical into Object.prototype. This can lead to corrupted configuration defaults, bypassed truthiness checks, denial of service, or logic corruption within the embedding application. This issue is specifically related to the architecture-beta diagram type.Recommendations
Update Mermaid to version 11.16.1.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mermaid