chore(deps): update dependency mermaid to v11.16.1 [security] #25

Merged
A-Guevara merged 1 commit from renovate/npm-mermaid-vulnerability into main 2026-08-12 16:18:13 +00:00
Member

This PR contains the following updates:

Package Change Age Confidence
mermaid 11.16.0 → 11.16.1 age confidence

Mermaid XY Charts are vulnerable to an infinite loop DoS

CVE-2026-71436 / GHSA-2v8p-3f2j-5mp7

More information

Details

Impact

Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the setXAxisRangeData(), when configuring an X-Axis with invalid parameters.

As each loop appends an element to an array, this would generally only cause an RangeError: Invalid array length to appear after a few seconds, but may cause the page/JavaScript process to crash due to memory exhaustion, depending on the environment.

Proof-of-concept
xychart
  x-axis 1 --> 1
  line [1, 2]
Patches

This has been patched in github.com/mermaid-js/mermaid@630aa7e5dd and released in Mermaid v11.16.1.

A backport has been made for the v10 branch in ef60adc837d9d5107af21285f01e83dea309bd0a and was released in Mermaid v10.9.8

Workarounds

There are no known workarounds. Please update to the latest version or apply the patch.

References

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Mermaid Architecture diagrams are vulnerable to prototype pollution

CVE-2026-71437 / GHSA-3rrr-jr9j-h3q3

More information

Details

Rendering an untrusted architecture-beta diagram lets the diagram author write an arbitrary property with the value horizontal or vertical onto Object.prototype. A group id of __proto__ is accepted as a valid parent.

Impact

Any code in the same realm that reads a property of that name from an arbitrary object, or enumerates an object with bare for...in, observes the injected value (which can only be the string horizontal or vertical.

This may mean corrupted option/config defaults, bypassed truthiness checks, causing denial of service or logic corruption in the embedding application.

Because the injected value cannot be an object or function, this is not directly exploitable for remote code execution.

PoC
architecture-beta
      group mermaidPrototypePollutionMarker(cloud)[Marker]
      service a(server)[A] in __proto__
      service b(server)[B] in mermaidPrototypePollutionMarker
      a:R -- L:b

The vulnerable write was introduced in commit cb0a4703bdf01d47508bde1c08aa9a980d70bc20 and first shipped in mermaid@11.5.0. The lines are unchanged in every release since.

Patches

This has been patched by github.com/mermaid-js/mermaid@99af3fc35e, released in Mermaid v11.16.1

Workarounds

There are no known workarounds. Please update to a patched version.

References

Are there any links users can visit to find out more?

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Mermaid allows CSS injection applying to sibling elements of the diagram

CVE-2026-50159 / GHSA-6x64-9x62-f2gx

More information

Details

Summary

Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with #mermaid-X, sibling (~ and +) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram <svg>.

Most users of mermaid would not be affected by this, as mermaid adds its <svg> as an only child of it's parent element. However, you may be affected if you manually insert the <svg> (or other elements) into the DOM yourself.

Details

Mermaid namespaces CSS through with a middleware intended to scope all rules to the diagram's SVG element. CSS nesting expands & ~ * { ... } to #svgId ~ *, which selects all sibling elements following the SVG in the DOM, outside the diagram boundary.

Impact

An attacker able to supply diagram source to a page (e.g., user-generated content rendered by Mermaid) could inject CSS rules affecting sibling elements to the diagram <svg> on the host page. This can be used for UI redressing, hiding content, conditional CSS-based probing, or phishing-style visual manipulation.

JavaScript execution is not possible via this vector.

Patches

This has been patched in github.com/mermaid-js/mermaid@12d472c9ed and released in Mermaid v11.16.1.

A backport has been made for the v10 branch in 7e83f1533318b307764d961906a73377266f4c5e and was released in Mermaid v10.9.8

Workarounds

If you are inserting the <svg> into the DOM yourself, you can wrap it in an element with no other children, e.g. <div><svg>...</svg></div> or element.innerHTML = svg. Alternatively, you can use mermaid.run() or mermaid.initialize() which will do this for you.

Setting "securityLevel": "sandbox" will also prevent this, or setting the secure config value in the mermaid config to avoid allowing diagrams to modify fontFamily, themeCSS, altFontFamily, and themeVariables.

To test, you can try using a themeCSS with & + * { /* my CSS here */} and see if it's applied outside of your mermaid <svg>.

---
config:
  themeCSS: |-
    & + * { background:red !important; width:100vw !important; height:100vh !important; position:fixed !important; inset:0 !important; }
---
info
References

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Mermaid configuration APIs allow prototype pollution

CVE-2026-71438 / GHSA-c4c3-pg64-4m4v

More information

Details

Summary

Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge the caller-supplied configuration object into Mermaid's internal config using the assignWithDepth deep-merge helper that is vulnerable to prototype pollution.

Because these APIs are intended to receive trusted configuration supplied by the application integrating Mermaid, Mermaid assesses the practical risk as low. The vulnerability is only reachable if an application forwards attacker-controlled data directly into one of these configuration entry points, which is outside their documented usage.

User-controlled configuration (e.g. configuration in diagram code using %%{init: {}}%% or YAML frontmatter) are already protected from prototype pollution.

Patches

This has been patched in github.com/mermaid-js/mermaid@2cd6dcf735 and released in Mermaid v11.16.1.

A backport has been made for the v10 branch in c34b07a0815842327e70794d69b0c8c5a1e2a956 and was released in Mermaid v10.9.8

Impact

Mermaid believes it's unlikely that anybody is impacted, as these functions are configuration entry points expected to receive trusted, developer-controlled values as they can modify other security-relevant configuration.

Workarounds

Don't pass user-controlled data to the mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig functions. Instead, users can use %%{init: {}}%% or YAML frontmatter in diagrams.

Reporters

Severity

  • CVSS Score: 2.4 / 10 (Low)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Mermaid radar diagrams are vulnerable to DoS

CVE-2026-71439 / GHSA-rhh3-jpg6-66xh

More information

Details

Impact

Mermaid radar diagrams allow arbitrary large values for ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.

Proof-of-concept
radar-beta
  axis a, b
  curve c {1, 1}
  ticks 1000000000
Patches

Has the problem been patched? What versions should users upgrade to?

This problem has been patched by github.com/mermaid-js/mermaid@59b22fad2b, which was released in Mermaid v11.16.1

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

There are no known workarounds without updating to a patched version of mermaid.

References

Are there any links users can visit to find out more?

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).

❗ Important

Release Notes retrieval for this PR were skipped because no github.com credentials were available.
If you are self-hosted, please see this instruction.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [mermaid](https://github.com/mermaid-js/mermaid) | [`11.16.0` → `11.16.1`](https://renovatebot.com/diffs/npm/mermaid/11.16.0/11.16.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/mermaid/11.16.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/mermaid/11.16.0/11.16.1?slim=true) | --- ### Mermaid XY Charts are vulnerable to an infinite loop DoS [CVE-2026-71436](https://nvd.nist.gov/vuln/detail/CVE-2026-71436) / [GHSA-2v8p-3f2j-5mp7](https://github.com/advisories/GHSA-2v8p-3f2j-5mp7) <details> <summary>More information</summary> #### Details ##### Impact Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the `setXAxisRangeData()`, when configuring an X-Axis with invalid parameters. As each loop appends an element to an array, this would generally only cause an `RangeError: Invalid array length` to appear after a few seconds, but may cause the page/JavaScript process to crash due to memory exhaustion, depending on the environment. ##### Proof-of-concept ```txt xychart x-axis 1 --> 1 line [1, 2] ``` ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 and released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in ef60adc837d9d5107af21285f01e83dea309bd0a and was released in [Mermaid v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Workarounds There are no known workarounds. Please update to the latest version or apply the patch. ##### References - https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 - https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a - https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7) - [https://github.com/mermaid-js/mermaid/pull/8022](https://github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289](https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289) - [https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a](https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a) - [https://github.com/mermaid-js/mermaid](https://github.com/mermaid-js/mermaid) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-2v8p-3f2j-5mp7) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid Architecture diagrams are vulnerable to prototype pollution [CVE-2026-71437](https://nvd.nist.gov/vuln/detail/CVE-2026-71437) / [GHSA-3rrr-jr9j-h3q3](https://github.com/advisories/GHSA-3rrr-jr9j-h3q3) <details> <summary>More information</summary> #### Details Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent. ##### Impact Any code in the same realm that reads a property of that name from an arbitrary object, or enumerates an object with bare `for...in`, observes the injected value (which can only be the string `horizontal` or `vertical`. This may mean corrupted option/config defaults, bypassed truthiness checks, causing denial of service or logic corruption in the embedding application. Because the injected value cannot be an object or function, this is not directly exploitable for remote code execution. ##### PoC ``` architecture-beta group mermaidPrototypePollutionMarker(cloud)[Marker] service a(server)[A] in __proto__ service b(server)[B] in mermaidPrototypePollutionMarker a:R -- L:b ``` The vulnerable write was introduced in commit [cb0a4703bdf01d47508bde1c08aa9a980d70bc20](https://github.com/mermaid-js/mermaid/commit/cb0a4703bdf01d47508bde1c08aa9a980d70bc20) and first shipped in `mermaid@11.5.0`. The lines are unchanged in every release since. ##### Patches This has been patched by https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf, released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) ##### Workarounds There are no known workarounds. Please update to a patched version. ##### References _Are there any links users can visit to find out more?_ - https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 #### Severity - CVSS Score: 6.5 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3) - [https://github.com/mermaid-js/mermaid/pull/8022](https://github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf](https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf) - [https://github.com/mermaid-js/mermaid](https://github.com/mermaid-js/mermaid) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-3rrr-jr9j-h3q3) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid allows CSS injection applying to sibling elements of the diagram [CVE-2026-50159](https://nvd.nist.gov/vuln/detail/CVE-2026-50159) / [GHSA-6x64-9x62-f2gx](https://github.com/advisories/GHSA-6x64-9x62-f2gx) <details> <summary>More information</summary> #### Details ##### Summary Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with `#mermaid-X`, sibling (`~` and `+`) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram `<svg>`. **Most users of mermaid would not be affected by this**, as mermaid adds its `<svg>` as an only child of it's parent element. However, you may be affected if you manually insert the `<svg>` (or other elements) into the DOM yourself. ##### Details Mermaid namespaces CSS through with a middleware intended to scope all rules to the diagram's SVG element. CSS nesting expands `& ~ * { ... }` to `#svgId ~ *`, which selects all sibling elements following the SVG in the DOM, outside the diagram boundary. ##### Impact An attacker able to supply diagram source to a page (e.g., user-generated content rendered by Mermaid) could inject CSS rules affecting sibling elements to the diagram `<svg>` on the host page. This can be used for UI redressing, hiding content, conditional CSS-based probing, or phishing-style visual manipulation. JavaScript execution is not possible via this vector. ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed and released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in 7e83f1533318b307764d961906a73377266f4c5e and was released in [Mermaid v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Workarounds If you are inserting the `<svg>` into the DOM yourself, you can wrap it in an element with no other children, e.g. `<div><svg>...</svg></div>` or `element.innerHTML = svg`. Alternatively, you can use `mermaid.run()` or `mermaid.initialize()` which will do this for you. Setting ["securityLevel": "sandbox"](https://mermaid.js.org/config/schema-docs/config.html#securitylevel) will also prevent this, or setting the [`secure`](https://mermaid.js.org/config/schema-docs/config.html#secure) config value in the mermaid config to avoid allowing diagrams to modify `fontFamily`, `themeCSS`, `altFontFamily`, and `themeVariables`. To test, you can try using a `themeCSS` with `& + * { /* my CSS here */}` and see if it's applied outside of your mermaid `<svg>`. ```mermaid-example --- config: themeCSS: |- & + * { background:red !important; width:100vw !important; height:100vh !important; position:fixed !important; inset:0 !important; } --- info ``` ##### References - GHSA-87f9-hvmw-gh4p/CVE-2026-41159 (related vulnerability) - https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 - https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e - https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx) - [https://github.com/mermaid-js/mermaid/pull/8022](https://github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed](https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed) - [https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e](https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e) - [https://github.com/mermaid-js/mermaid](https://github.com/mermaid-js/mermaid) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-6x64-9x62-f2gx) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid configuration APIs allow prototype pollution [CVE-2026-71438](https://nvd.nist.gov/vuln/detail/CVE-2026-71438) / [GHSA-c4c3-pg64-4m4v](https://github.com/advisories/GHSA-c4c3-pg64-4m4v) <details> <summary>More information</summary> #### Details ##### Summary Mermaid's configuration setters (`mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig`) merge the caller-supplied configuration object into Mermaid's internal config using the `assignWithDepth` deep-merge helper that is vulnerable to prototype pollution. Because these APIs are intended to receive **trusted** configuration supplied by the application integrating Mermaid, Mermaid assesses the practical risk as **low**. The vulnerability is only reachable if an application forwards attacker-controlled data directly into one of these configuration entry points, which is outside their documented usage. User-controlled configuration (e.g. configuration in diagram code using `%%{init: {}}%%` or YAML frontmatter) are already protected from prototype pollution. ##### Patches This has been patched in https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43 and released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1). A backport has been made for the v10 branch in c34b07a0815842327e70794d69b0c8c5a1e2a956 and was released in [Mermaid v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) ##### Impact Mermaid believes it's unlikely that anybody is impacted, as these functions are configuration entry points expected to receive trusted, developer-controlled values as they can modify other security-relevant configuration. ##### Workarounds Don't pass user-controlled data to the `mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig` functions. Instead, users can use `%%{init: {}}%%` or YAML frontmatter in diagrams. ##### Reporters - liyi.zhou@sydney.edu.au (Liyi), https://lzhou1110.github.io/ - ziyue0530@&#8203;gmail.com (Ziyue), https://zyy0530.github.io/ - cshe0476@&#8203;uni.sydney.edu.au (Strick), https://str1ckl4nd.github.io/ - chng0012@&#8203;uni.sydney.edu.au (Maurice), http://maurice.busystar.org/ - cyu210608@&#8203;gmail.com (Chenchen), https://7thparkk.github.io/ #### Severity - CVSS Score: 2.4 / 10 (Low) - Vector String: `CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v) - [https://github.com/mermaid-js/mermaid/pull/8022](https://github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43](https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43) - [https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956](https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956) - [https://github.com/mermaid-js/mermaid](https://github.com/mermaid-js/mermaid) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) - [https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-c4c3-pg64-4m4v) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Mermaid radar diagrams are vulnerable to DoS [CVE-2026-71439](https://nvd.nist.gov/vuln/detail/CVE-2026-71439) / [GHSA-rhh3-jpg6-66xh](https://github.com/advisories/GHSA-rhh3-jpg6-66xh) <details> <summary>More information</summary> #### Details ##### Impact Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory. ##### Proof-of-concept ```txt radar-beta axis a, b curve c {1, 1} ticks 1000000000 ``` ##### Patches _Has the problem been patched? What versions should users upgrade to?_ This problem has been patched by https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e, which was released in [Mermaid v11.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) ##### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There are no known workarounds without updating to a patched version of mermaid. ##### References _Are there any links users can visit to find out more?_ - https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e - https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1 #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L` #### References - [https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh) - [https://github.com/mermaid-js/mermaid/pull/8022](https://github.com/mermaid-js/mermaid/pull/8022) - [https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e](https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e) - [https://github.com/mermaid-js/mermaid](https://github.com/mermaid-js/mermaid) - [https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1](https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-rhh3-jpg6-66xh) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> > :exclamation: **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzguMiIsInVwZGF0ZWRJblZlciI6IjQzLjI3OC4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJzZWN1cml0eS92dWxuIl19-->
chore(deps): update dependency mermaid to v11.16.1 [security]
Some checks failed
baseline-security / baseline (push) Failing after 1m27s
scan / trivy-fs (push) Failing after 56s
baseline-security / baseline (pull_request) Failing after 1m3s
scan / trivy-fs (pull_request) Failing after 46s
ai-review / review (pull_request) Successful in 3m3s
1e3773c33a
ai-review-bot left a comment

AI review · advisory

Verdict: 2 things worth fixing (2 low).

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 1 refuted · web: 1 queries, 2 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Panel debate — how this review was reached

Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97): The diff only updates version numbers, cleans up lockfile entries, and adds optional peer dependencies without introducing functional changes or issues.
  • Gemma 4 31B (0 findings, confidence 1.0): The diff is a standard dependency update for the mermaid package (v11.16.0 -> v11.16.1) and a corresponding project version bump; no correctness, security, or best-practice issues were found in the
  • Devstral 2 123B (1 finding, confidence 0.9): The PR updates the mermaid dependency to v11.16.1, but the integrity of the new version has not been verified, which could pose a security risk.
  • Laguna S 2.1 (2 findings, confidence 0.92): The PR is a generated lockfile refresh from a dependabot-style mermaid security bump; the substantive changes (mermaid 11.16.0→11.16.1 + two transitive deps under @nuxt/cli) are correct and the remove

Web grounding — web: 1 queries, 2 results: «https://registry.npmjs.org/mermaid/-/mermaid-11.16.1.tgz»

Round 2 — cross-examination

  • Devstral 2 123B#1 Mermaid version bump without integrity verification · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1
  • Laguna S 2.1#2 package.json mermaid range unchanged despite security-motivated bump · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: —
  • Laguna S 2.1#1 Version bump not reflected in package.json · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: —

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Mermaid version bump without integrity verification — The lockfile includes an integrity SHA512 checksum for the new mermaid version, satisfying the requirement to verify the published checksum before use

Synthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.

Transcript rv-20260807052439-4e1a01 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript rv-20260807052439-4e1a01.

### AI review · advisory **Verdict: 2 things worth fixing** (2 low). <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 1 refuted · web: 1 queries, 2 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less) **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97): The diff only updates version numbers, cleans up lockfile entries, and adds optional peer dependencies without introducing functional changes or issues. - **Gemma 4 31B** (0 findings, confidence 1.0): The diff is a standard dependency update for the `mermaid` package (v11.16.0 -> v11.16.1) and a corresponding project version bump; no correctness, security, or best-practice issues were found in the - **Devstral 2 123B** (1 finding, confidence 0.9): The PR updates the mermaid dependency to v11.16.1, but the integrity of the new version has not been verified, which could pose a security risk. - **Laguna S 2.1** (2 findings, confidence 0.92): The PR is a generated lockfile refresh from a dependabot-style mermaid security bump; the substantive changes (mermaid 11.16.0→11.16.1 + two transitive deps under @nuxt/cli) are correct and the remove **Web grounding** — web: 1 queries, 2 results: «https://registry.npmjs.org/mermaid/-/mermaid-11.16.1.tgz» **Round 2 — cross-examination** - `Devstral 2 123B#1` Mermaid version bump without integrity verification · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 - `Laguna S 2.1#2` package.json mermaid range unchanged despite security-motivated bump · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: — - `Laguna S 2.1#1` Version bump not reflected in package.json · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: — **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Mermaid version bump without integrity verification — The lockfile includes an integrity SHA512 checksum for the new mermaid version, satisfying the requirement to verify the published checksum before use **Synthesis** — Devstral 2 123B wrote the final review from 2 confirmed findings. <sub>Transcript `rv-20260807052439-4e1a01` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript `rv-20260807052439-4e1a01`.</sub>
@ -2,3 +2,3 @@
"name": "tti-ux",
"version": "1.6.0",
"version": "1.7.0",
"lockfileVersion": 3,
Member

package-lock.json:4 · LOW — Version bump not reflected in package.json
The lockfile was updated to version 1.7.0, but package.json still shows 1.6.0. This mismatch can cause npm ci to warn or fail because the lockfile and manifest disagree.

Fix: Update the "version" field in package.json to "1.7.0" to match the lockfile, or run npm version patch to sync both files.

panel tally 4/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:4`** · LOW — Version bump not reflected in package.json The lockfile was updated to version 1.7.0, but package.json still shows 1.6.0. This mismatch can cause `npm ci` to warn or fail because the lockfile and manifest disagree. > **Fix:** Update the `"version"` field in package.json to `"1.7.0"` to match the lockfile, or run `npm version patch` to sync both files. <sub>panel tally 4/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260807052439-4e1a01:Laguna S 2.1#1 -->
@ -14289,9 +14128,9 @@
}
Member

package-lock.json:14128 · LOW — package.json mermaid range unchanged despite security-motivated bump
The PR bumps mermaid from 11.16.0 to 11.16.1 for security, but package.json still allows any 11.14.x version (^11.14.0). A fresh install could pull an older, vulnerable version.

Fix: Update the mermaid range in package.json to "^11.16.1" and run npm install to enforce the secure version.

panel tally 4/4 · reply here or use the finding board to agree/disagree

**`package-lock.json:14128`** · LOW — package.json mermaid range unchanged despite security-motivated bump The PR bumps mermaid from 11.16.0 to 11.16.1 for security, but package.json still allows any 11.14.x version (`^11.14.0`). A fresh install could pull an older, vulnerable version. > **Fix:** Update the mermaid range in package.json to `"^11.16.1"` and run `npm install` to enforce the secure version. <sub>panel tally 4/4 · reply here or use the finding board to agree/disagree</sub> <!-- tti-rv:rv-20260807052439-4e1a01:Laguna S 2.1#2 -->
Owner

Admin-merging: this security fix cannot go green because the required baseline gate fails on the pre-existing tree backlog it is part of fixing (deadlock documented in #28). Lockfile-only bump, reviewed.

Admin-merging: this security fix cannot go green because the required baseline gate fails on the pre-existing tree backlog it is part of fixing (deadlock documented in #28). Lockfile-only bump, reviewed.
A-Guevara deleted branch renovate/npm-mermaid-vulnerability 2026-08-12 16:18:14 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!25
No description provided.