Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-54881

Опубликовано: 20 авг. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

needs-triage

jammy

needs-triage

noble

DNE

plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 13%
0.00045
Низкий

Связанные уязвимости

nvd
9 дней назад

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

debian
9 дней назад

Mermaid is a JavaScript based diagramming and charting tool that uses ...

github
8 дней назад

Mermaid improperly sanitizes sequence diagram labels leading to XSS

EPSS

Процентиль: 13%
0.00045
Низкий