CVE-2021-43861
Dashboard / Vulnerabilities / CVE-2021-43861
Summary:
Details: Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.
References: https://github.com/mermaid-js/mermaid/releases/tag/8.13.8, https://github.com/mermaid-js/mermaid/security/advisories/GHSA-p3rp-vmj9-gv6v, https://github.com/mermaid-js/mermaid/commit/066b7a0d0bda274d94a2f2d21e4323dab5776d83
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
8.13.7
8.13.6
8.13.5
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
