Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6x64-9x62-f2gx | Mermaid allows CSS injection applying to sibling elements of the diagram |
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1. | |
| Title | Mermaid allows CSS injection applying to sibling elements of the diagram | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-06T19:55:27.994Z
Reserved: 2026-06-03T20:54:20.432Z
Link: CVE-2026-50159
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:15:05Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')
Github GHSA