{"id":"GHSA-w32g-5hqp-gg6q","summary":"Cross-Site Scripting in mermaid","details":"Versions of `mermaid` prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input  such as `A[\"\u003cimg src=invalid onerror=alert('XSS')\u003e\u003c/img\u003e\"] ` is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.\n\n\n## Recommendation\n\nUpgrade to version 8.2.3 or later","modified":"2021-09-27T13:34:07Z","published":"2020-09-02T15:41:41Z","database_specific":{"github_reviewed_at":"2020-08-31T18:34:30Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/knsv/mermaid/issues/847"},{"type":"PACKAGE","url":"https://github.com/knsv/mermaid"},{"type":"WEB","url":"https://www.npmjs.com/advisories/751"}],"affected":[{"package":{"name":"mermaid","ecosystem":"npm","purl":"pkg:npm/mermaid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.2.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-w32g-5hqp-gg6q/GHSA-w32g-5hqp-gg6q.json"}}],"schema_version":"1.9.0"}