{"id":"UBUNTU-CVE-2025-54881","details":"Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.","modified":"2025-09-08T17:11:58Z","published":"2025-08-19T17:15:00Z","upstream":["CVE-2025-54881"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-54881"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-54881"},{"type":"REPORT","url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh"},{"type":"REPORT","url":"https://github.com/mermaid-js/mermaid/commit/5c69e5fdb004a6d0a2abe97e23d26e223a059832"},{"type":"REPORT","url":"https://github.com/mermaid-js/mermaid/commit/685516a85ec1df64cefd4fd15f26533be87d458e"}],"affected":[{"package":{"name":"node-mermaid","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-mermaid@8.13.8+~cs10.4.16-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.7.0+ds+~cs27.17.17-3","8.13.3+ds+~cs26.13.21-1","8.13.3+ds+~cs26.13.21-2","8.13.8+~cs10.4.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"node-mermaid","binary_version":"8.13.8+~cs10.4.16-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54881.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"},{"type":"Ubuntu","score":"medium"}]}