CVE-2025-54881
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.
Open
LOW (0.3)System detected CVE-2025-54881
System
System updated the risk assessment from 0 to 0.32
System recalculated raw risk assessment
System updated the risk assessment from 0.32 to 0.65
System recalculated raw risk assessment
System fixed CVE-2025-54881
System detected CVE-2025-54881 with a risk of 0.32
Add a comment
Last calculated at:
Affected component
mermaid
Quick Fix
Update all Dependencies
Update only mermaid