← Zurück zur CVE-Suche

CVE-2026-41159

Mermaid

Beschreibung

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid-s default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis-s & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @counter-style) are also injectable as stylis hoists them to top level. This allows page defacement and DOM attribute exfiltration via CSS :has() selectors. This vulnerability is fixed in 10.9.6 and 11.15.0.

CVSS 5.3EPSS 0.398%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-05-29 15:16:22
Betroffene Versionen
cannotmatch
Typ
Package
Zuletzt geändert
2026-07-21 12:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L