chore(deps): update dependency mermaid to v11.16.1 [security] #25
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!25
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/npm-mermaid-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
11.16.0→11.16.1Mermaid XY Charts are vulnerable to an infinite loop DoS
CVE-2026-71436 / GHSA-2v8p-3f2j-5mp7
More information
Details
Impact
Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the
setXAxisRangeData(), when configuring an X-Axis with invalid parameters.As each loop appends an element to an array, this would generally only cause an
RangeError: Invalid array lengthto appear after a few seconds, but may cause the page/JavaScript process to crash due to memory exhaustion, depending on the environment.Proof-of-concept
Patches
This has been patched in
github.com/mermaid-js/mermaid@630aa7e5ddand released in Mermaid v11.16.1.A backport has been made for the v10 branch in ef60adc837d9d5107af21285f01e83dea309bd0a and was released in Mermaid v10.9.8
Workarounds
There are no known workarounds. Please update to the latest version or apply the patch.
References
github.com/mermaid-js/mermaid@630aa7e5ddgithub.com/mermaid-js/mermaid@ef60adc837Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Mermaid Architecture diagrams are vulnerable to prototype pollution
CVE-2026-71437 / GHSA-3rrr-jr9j-h3q3
More information
Details
Rendering an untrusted
architecture-betadiagram lets the diagram author write an arbitrary property with the valuehorizontalorverticalontoObject.prototype. A group id of__proto__is accepted as a valid parent.Impact
Any code in the same realm that reads a property of that name from an arbitrary object, or enumerates an object with bare
for...in, observes the injected value (which can only be the stringhorizontalorvertical.This may mean corrupted option/config defaults, bypassed truthiness checks, causing denial of service or logic corruption in the embedding application.
Because the injected value cannot be an object or function, this is not directly exploitable for remote code execution.
PoC
The vulnerable write was introduced in commit cb0a4703bdf01d47508bde1c08aa9a980d70bc20 and first shipped in
mermaid@11.5.0. The lines are unchanged in every release since.Patches
This has been patched by
github.com/mermaid-js/mermaid@99af3fc35e, released in Mermaid v11.16.1Workarounds
There are no known workarounds. Please update to a patched version.
References
Are there any links users can visit to find out more?
github.com/mermaid-js/mermaid@99af3fc35eSeverity
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Mermaid allows CSS injection applying to sibling elements of the diagram
CVE-2026-50159 / GHSA-6x64-9x62-f2gx
More information
Details
Summary
Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with
#mermaid-X, sibling (~and+) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram<svg>.Most users of mermaid would not be affected by this, as mermaid adds its
<svg>as an only child of it's parent element. However, you may be affected if you manually insert the<svg>(or other elements) into the DOM yourself.Details
Mermaid namespaces CSS through with a middleware intended to scope all rules to the diagram's SVG element. CSS nesting expands
& ~ * { ... }to#svgId ~ *, which selects all sibling elements following the SVG in the DOM, outside the diagram boundary.Impact
An attacker able to supply diagram source to a page (e.g., user-generated content rendered by Mermaid) could inject CSS rules affecting sibling elements to the diagram
<svg>on the host page. This can be used for UI redressing, hiding content, conditional CSS-based probing, or phishing-style visual manipulation.JavaScript execution is not possible via this vector.
Patches
This has been patched in
github.com/mermaid-js/mermaid@12d472c9edand released in Mermaid v11.16.1.A backport has been made for the v10 branch in 7e83f1533318b307764d961906a73377266f4c5e and was released in Mermaid v10.9.8
Workarounds
If you are inserting the
<svg>into the DOM yourself, you can wrap it in an element with no other children, e.g.<div><svg>...</svg></div>orelement.innerHTML = svg. Alternatively, you can usemermaid.run()ormermaid.initialize()which will do this for you.Setting "securityLevel": "sandbox" will also prevent this, or setting the
secureconfig value in the mermaid config to avoid allowing diagrams to modifyfontFamily,themeCSS,altFontFamily, andthemeVariables.To test, you can try using a
themeCSSwith& + * { /* my CSS here */}and see if it's applied outside of your mermaid<svg>.References
github.com/mermaid-js/mermaid@12d472c9edgithub.com/mermaid-js/mermaid@7e83f15333Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Mermaid configuration APIs allow prototype pollution
CVE-2026-71438 / GHSA-c4c3-pg64-4m4v
More information
Details
Summary
Mermaid's configuration setters (
mermaid.initialize,mermaidAPI.setConfig, andmermaidAPI.updateSiteConfig) merge the caller-supplied configuration object into Mermaid's internal config using theassignWithDepthdeep-merge helper that is vulnerable to prototype pollution.Because these APIs are intended to receive trusted configuration supplied by the application integrating Mermaid, Mermaid assesses the practical risk as low. The vulnerability is only reachable if an application forwards attacker-controlled data directly into one of these configuration entry points, which is outside their documented usage.
User-controlled configuration (e.g. configuration in diagram code using
%%{init: {}}%%or YAML frontmatter) are already protected from prototype pollution.Patches
This has been patched in
github.com/mermaid-js/mermaid@2cd6dcf735and released in Mermaid v11.16.1.A backport has been made for the v10 branch in c34b07a0815842327e70794d69b0c8c5a1e2a956 and was released in Mermaid v10.9.8
Impact
Mermaid believes it's unlikely that anybody is impacted, as these functions are configuration entry points expected to receive trusted, developer-controlled values as they can modify other security-relevant configuration.
Workarounds
Don't pass user-controlled data to the
mermaid.initialize,mermaidAPI.setConfig, andmermaidAPI.updateSiteConfigfunctions. Instead, users can use%%{init: {}}%%or YAML frontmatter in diagrams.Reporters
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Mermaid radar diagrams are vulnerable to DoS
CVE-2026-71439 / GHSA-rhh3-jpg6-66xh
More information
Details
Impact
Mermaid radar diagrams allow arbitrary large values for
ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.Proof-of-concept
Patches
Has the problem been patched? What versions should users upgrade to?
This problem has been patched by
github.com/mermaid-js/mermaid@59b22fad2b, which was released in Mermaid v11.16.1Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
There are no known workarounds without updating to a patched version of mermaid.
References
Are there any links users can visit to find out more?
github.com/mermaid-js/mermaid@59b22fad2bSeverity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
AI review · advisory
Verdict: 2 things worth fixing (2 low).
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 2 confirmed, 1 refuted · web: 1 queries, 2 results · context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Panel debate — how this review was reached
Grounding — context: 1 files · 90 codebase · 14 standards chunks (best-grounded: GPT-OSS 120B; smaller windows saw less)
Round 1 — independent reviews
mermaidpackage (v11.16.0 -> v11.16.1) and a corresponding project version bump; no correctness, security, or best-practice issues were found in theWeb grounding — web: 1 queries, 2 results: «https://registry.npmjs.org/mermaid/-/mermaid-11.16.1.tgz»
Round 2 — cross-examination
Devstral 2 123B#1Mermaid version bump without integrity verification · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1Laguna S 2.1#2package.json mermaid range unchanged despite security-motivated bump · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: —Laguna S 2.1#1Version bump not reflected in package.json · confirmed: GPT-OSS 120B, Gemma 4 31B, Devstral 2 123B · refuted: —Raised but refuted (left out of the review above)
Devstral 2 123B#1Mermaid version bump without integrity verification — The lockfile includes an integrity SHA512 checksum for the new mermaid version, satisfying the requirement to verify the published checksum before useSynthesis — Devstral 2 123B wrote the final review from 2 confirmed findings.
Transcript
rv-20260807052439-4e1a01— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Disagree with a finding? Reply on it, or use the finding board under this review. Transcript
rv-20260807052439-4e1a01.@ -2,3 +2,3 @@"name": "tti-ux","version": "1.6.0","version": "1.7.0","lockfileVersion": 3,package-lock.json:4· LOW — Version bump not reflected in package.jsonThe lockfile was updated to version 1.7.0, but package.json still shows 1.6.0. This mismatch can cause
npm cito warn or fail because the lockfile and manifest disagree.panel tally 4/4 · reply here or use the finding board to agree/disagree
@ -14289,9 +14128,9 @@}package-lock.json:14128· LOW — package.json mermaid range unchanged despite security-motivated bumpThe PR bumps mermaid from 11.16.0 to 11.16.1 for security, but package.json still allows any 11.14.x version (
^11.14.0). A fresh install could pull an older, vulnerable version.panel tally 4/4 · reply here or use the finding board to agree/disagree
Admin-merging: this security fix cannot go green because the required baseline gate fails on the pre-existing tree backlog it is part of fixing (deadlock documented in #28). Lockfile-only bump, reviewed.