Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28574 | Mermaid improperly sanitizes sequence diagram labels leading to XSS |
Github GHSA |
GHSA-7rqq-prvp-x9jh | Mermaid improperly sanitizes sequence diagram labels leading to XSS |
Tue, 19 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS. | |
| Title | Mermaid improperly sanitizes of sequence diagram labels leading to XSS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-19T18:14:04.599Z
Reserved: 2025-07-31T17:23:33.475Z
Link: CVE-2025-54881
Updated: 2025-08-19T18:11:46.924Z
Status : Deferred
Published: 2025-08-19T17:15:41.247
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54881
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA