{"id":"CVE-2026-41149","aliases":["GHSA-ghcm-xqfw-q4vr"],"url":"https://o3.security/vulnerability/CVE-2026-41149","summary":"Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection","details":"Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If developers are unable to immediately upgrade, they can work around this issue by setting \"securityLevel\": \"sandbox\", which prevents the issue by rendering the mermaid diagram in a sandboxed <iframe>.","published":"2026-05-22T22:34:36.944Z","modified":"2026-08-12T03:51:36.021445595Z","cvss":null,"epss":{"score":0.00401,"percentile":0.33938,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mermaid","fixedVersion":"11.15.0"},{"ecosystem":"npm","name":"mermaid","fixedVersion":"10.9.6"}],"fix":{"url":"https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056","label":"mermaid-js/mermaid@37ff937"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41149.json"},{"type":"ADVISORY","url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41149"},{"type":"FIX","url":"https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056"},{"type":"FIX","url":"https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3"},{"type":"PACKAGE","url":"https://github.com/mermaid-js/mermaid"},{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0"},{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6"},{"type":"WEB","url":"https://mermaid.js.org/config/schema-docs/config.html#securitylevel"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.021445595Z"}}