{"id":"GHSA-39h7-pwv7-rc3x","aliases":[],"url":"https://o3.security/vulnerability/GHSA-39h7-pwv7-rc3x","summary":"Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)","details":"### Impact\n\n`@excalidraw/excalidraw@0.18.0` depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could trigger XSS through Mermaid’s KaTeX label rendering path.\n\nThis is patched in `@excalidraw/excalidraw@0.18.1` by updating `@excalidraw/mermaid-to-excalidraw` to `2.2.2`, which uses a patched Mermaid 11 release.\n\nModerate severity as this XSS requires manual user action - pasting unsafe Mermaid diagram into the Excalidraw editor. No semi-automated attack vector exists by default (such as accessing a link).\n\n### Patches\n\n- Stable `@excalidraw/excalidraw@0.18.1` is patched.\n- Unstable `@excalidraw/excalidraw@next` has resolved to patched builds since `@excalidraw/excalidraw@0.18.0-f29edf` on 2025-08-21.\n- Direct consumers of `@excalidraw/mermaid-to-excalidraw` should use `1.1.3` or later.\n\n### Workarounds\n\nNone.\n\n### Resources\n\n- Upstream Mermaid advisory: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh\n- CVE-2025-54881","published":"2026-04-24T20:41:51Z","modified":"2026-05-05T16:02:23.084098Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@excalidraw/excalidraw","fixedVersion":"0.18.1"},{"ecosystem":"npm","name":"@excalidraw/mermaid-to-excalidraw","fixedVersion":"1.1.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/excalidraw/excalidraw/security/advisories/GHSA-39h7-pwv7-rc3x"},{"type":"WEB","url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh"},{"type":"PACKAGE","url":"https://github.com/excalidraw/excalidraw"},{"type":"WEB","url":"https://github.com/excalidraw/excalidraw/releases/tag/v0.18.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-05T16:02:23.084098Z"}}