/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-54881

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-54881

Severity

Unknown

Summary

Mermaid improperly sanitizes of sequence diagram labels leading to XSS

Description

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing