{"id":"CVE-2025-54881","aliases":["GHSA-7rqq-prvp-x9jh"],"url":"https://o3.security/vulnerability/CVE-2025-54881","summary":"Mermaid improperly sanitizes of sequence diagram labels leading to XSS","details":"Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.","published":"2025-08-19T17:04:29.453Z","modified":"2026-08-12T03:51:16.849147255Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mermaid","fixedVersion":"11.10.0"},{"ecosystem":"npm","name":"mermaid","fixedVersion":"10.9.4"}],"fix":{"url":"https://github.com/mermaid-js/mermaid/commit/5c69e5fdb004a6d0a2abe97e23d26e223a059832","label":"mermaid-js/mermaid@5c69e5f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54881.json"},{"type":"ADVISORY","url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54881"},{"type":"FIX","url":"https://github.com/mermaid-js/mermaid/commit/5c69e5fdb004a6d0a2abe97e23d26e223a059832"},{"type":"FIX","url":"https://github.com/mermaid-js/mermaid/commit/685516a85ec1df64cefd4fd15f26533be87d458e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.849147255Z"}}