← Πίσω στην αναζήτηση CVE

CVE-2026-41159

Mermaid

Περιγραφή

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid-s default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis-s & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @counter-style) are also injectable as stylis hoists them to top level. This allows page defacement and DOM attribute exfiltration via CSS :has() selectors. This vulnerability is fixed in 10.9.6 and 11.15.0.

CVSS 5.3EPSS 0.398%Κίνδυνος 0.55
Προβολή πηγής
Δημοσίευση
2026-05-29 15:16:22
Επηρεαζόμενες εκδόσεις
cannotmatch
Τύπος
Package
Τελευταία τροποποίηση
2026-07-21 12:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L