Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50159

Опубликовано: 06 авг. 2026
Источник: nvd
EPSS Низкий

Описание

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

EPSS

Процентиль: 44%
0.00569
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
3 дня назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

debian
3 дня назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...

github
3 дня назад

Mermaid allows CSS injection applying to sibling elements of the diagram

EPSS

Процентиль: 44%
0.00569
Низкий

Дефекты

CWE-94