CVE-2025-54881

EUVD-2025-28574
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 52.56%
Debian logo
Debian Releases
Debian Product
Codename
node-mermaid
bullseye
8.7.0+ds+~cs27.17.17-3+deb11u2
fixed
forky
9.2.2+~2.0.0-2
fixed
sid
9.2.2+~2.0.0-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-mermaid
jammy
needs-triage
noble
dne
plucky
dne
questing
dne
resolute
dne