Cross-Site Scripting in diagram-jsGHSA-8fw4-xh83-3j6q
Fix: bpmn-io/diagram-js@2565c40GHSA-8fw4-xh83-3j6q is a security vulnerability in diagram-js. A fix is available for diagram-js — see the affected versions and patch details below.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
diagram-jsnpmDescription
Versions of diagram-js prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x) are vulnerable to Cross-Site Scripting. The package fails to escape output of user-controlled input in search-pad, allowing attackers to execute arbitrary JavaScript.
Recommendation
If you are using diagram-js 3.x, upgrade to version 3.3.1. If you are using diagram-js 2.x, upgrade to version 2.6.2.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | diagram-js | all versions | 2.6.2npm install diagram-js@2.6.2 |
| 📦npm | diagram-js | ≥ 3.0.0&&< 3.3.1 | 3.3.1npm install diagram-js@3.3.1 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for diagram-js, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update diagram-js to 2.6.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-8fw4-xh83-3j6q is resolved across your whole dependency graph.
Workarounds
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Frequently Asked Questions
Is GHSA-8fw4-xh83-3j6q in your dependencies?
Find it across npm, including transitive dependencies.