PT-2021-23984 · Mermaid · Mermaid
Knsv
·
Published
2021-12-30
·
Updated
2023-07-21
·
CVE-2021-43861
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Mermaid versions prior to 8.13.8
Description:
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Malicious diagrams can run javascript code at diagram readers' machines.
Recommendations:
For versions prior to 8.13.8, upgrade to version 8.13.8 to receive a patch.
At the moment, there is no other information about additional mitigation measures aside from upgrading to the patched version.
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mermaid