{"id":"GHSA-w32g-5hqp-gg6q","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w32g-5hqp-gg6q","summary":"Cross-Site Scripting in mermaid","details":"Versions of `mermaid` prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input  such as `A[\"<img src=invalid onerror=alert('XSS')></img>\"] ` is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.\n\n\n## Recommendation\n\nUpgrade to version 8.2.3 or later","published":"2020-09-02T15:41:41Z","modified":"2021-09-27T13:34:07Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mermaid","fixedVersion":"8.2.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/knsv/mermaid/issues/847"},{"type":"PACKAGE","url":"https://github.com/knsv/mermaid"},{"type":"WEB","url":"https://www.npmjs.com/advisories/751"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-27T13:34:07Z"}}