Markdown-ish syntax for generating flowcharts, mindmaps, sequence diagrams, class diagrams, gantt charts, git graphs and more.
93%
Total Score
100
51
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-71439 mermaid is vulnerable to Unchecked Input for Loop Condition in versions 11.6.0 - 11.16.1. | 11.6.0 - 11.16.1 | Medium |
CVE-2026-71438 mermaid is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 11.0.0-alpha.1 - 11.16.1 and 0.0.0 - 10.9.8. | 0.0.0 - 10.9.811.0.0-alpha.1 - 11.16.1 | Low |
CVE-2026-50159 mermaid is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 11.0.0-alpha.1 - 11.16.1 and 0.0.0 - 10.9.8. | 0.0.0 - 10.9.811.0.0-alpha.1 - 11.16.1 | Medium |
CVE-2026-71437 mermaid is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 11.5.0 - 11.16.1. | 11.5.0 - 11.16.1 | Medium |
CVE-2026-71436 mermaid is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 10.6.0 - 10.9.8 and 11.0.0-alpha.1 - 11.16.1. | 10.6.0 - 10.9.811.0.0-alpha.1 - 11.16.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
d3 Version ^7.9.0 | — | — |
uuid Version ^11.1.0 || ^12 || ^13 || ^14.0.0 | — | — |
dayjs Version ^1.11.21 | — | — |
katex Version ^0.16.47 | — | — |
khroma Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant