A AegiFlow
MEDIUMCVSS 5.3EPSS 0.6%

CVE-2026-50159

CVE-2026-50159 updated by NVD

Published
2026-08-06
Modified
2026-09-10
EPSS percentile
44%
Sources
github-advisory, nvd

Summary

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmmermaid11.16.1, 10.9.8

Remediation: Upgrade to 11.16.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.