PT-2021-23984 · Mermaid · Mermaid

Knsv

·

Published

2021-12-30

·

Updated

2023-07-21

·

CVE-2021-43861

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mermaid versions prior to 8.13.8
Description: Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Malicious diagrams can run javascript code at diagram readers' machines.
Recommendations: For versions prior to 8.13.8, upgrade to version 8.13.8 to receive a patch. At the moment, there is no other information about additional mitigation measures aside from upgrading to the patched version.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-43861
GHSA-P3RP-VMJ9-GV6V

Affected Products

Mermaid