Incorrect sanitisation function leads to `XSS` in mermaid
Description
Published by the National Vulnerability Database
Dec 30, 2021
Reviewed
Jan 6, 2022
Published to the GitHub Advisory Database
Jan 6, 2022
Last updated
Feb 3, 2023
Impact
Malicious diagrams can contain javascript code that can be run at diagram readers machines.
Patches
The users should upgrade to version 8.13.8
Workarounds
You need to upgrade in order to avoid this issue.
References