NONE · 0

CVE-2025-54881

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 1...

Vulnerability Description

Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-54881?

CVE-2025-54881 is a documented vulnerability. Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 1...

How severe is CVE-2025-54881?

CVSS scoring is not yet available for CVE-2025-54881. Check NVD for updates.

Is there a patch for CVE-2025-54881?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.