Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-50159

Опубликовано: 07 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

jammy

needs-triage

noble

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 44%
0.00569
Низкий

Связанные уязвимости

nvd
3 дня назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

debian
3 дня назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...

github
3 дня назад

Mermaid allows CSS injection applying to sibling elements of the diagram

EPSS

Процентиль: 44%
0.00569
Низкий