{"id":"GHSA-p3rp-vmj9-gv6v","summary":"Incorrect sanitisation function leads to `XSS` in mermaid","details":"### Impact\nMalicious diagrams can contain javascript code that can be run at diagram readers machines.\n\n### Patches\nThe users should upgrade to version 8.13.8\n\n### Workarounds\nYou need to upgrade in order to avoid this issue.\n","aliases":["CVE-2021-43861"],"modified":"2026-07-08T06:28:14.087175466Z","published":"2022-01-06T19:45:59Z","database_specific":{"nvd_published_at":"2021-12-30T14:15:00Z","cwe_ids":["CWE-20","CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-01-06T19:02:22Z"},"references":[{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-p3rp-vmj9-gv6v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43861"},{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/commit/066b7a0d0bda274d94a2f2d21e4323dab5776d83"},{"type":"PACKAGE","url":"https://github.com/mermaid-js/mermaid"},{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/releases/tag/8.13.8"}],"affected":[{"package":{"name":"mermaid","ecosystem":"npm","purl":"pkg:npm/mermaid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.13.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-p3rp-vmj9-gv6v/GHSA-p3rp-vmj9-gv6v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}