CVE-2021-43861

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
3.5
LOW
Affected
1
PROJECT

Description

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

Generation of diagrams like flowcharts or sequence diagrams from text in a similar manner as markdown
GitHubGitHub
88.9K