Mermaid is a lightweight diagram-rendering library embedded across documentation platforms, wikis, and development tools, where its parser-facing role exposes it to input-validation challenges. The recurring vulnerability surface centers on cross-site scripting, code injection, and input-validation weaknesses characteristic of a markdown-like DSL processor, alongside occasional parser robustness issues such as infinite loops. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mermaid Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41150MEDIUM Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when render | May 29, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-41159MEDIUM Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecti | May 29, 2026 | 5.3 | 25 | NO | NO |
CVE-2025-54880MEDIUM Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default config | Aug 19, 2025 | 6.1 | 22 | NO | NO |
CVE-2022-31108MEDIUM Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. An attacker is able t | Jun 28, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-35513MEDIUM Mermaid before 8.11.0 allows XSS when the antiscript feature is used. | Jun 27, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-43861MEDIUM Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13 | Dec 30, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mermaid Project.
Media articles that mention a CVE ID that affects a product developed by Mermaid Project — matched by CVE ID, not by vendor name.