Markdown-ish syntax for generating flowcharts, mindmaps, sequence diagrams, class diagrams, gantt charts, git graphs and more.
91%
Total Score
61
95
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41159 mermaid is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 11.0.0-alpha.1 - 11.14.0 and 0.0.0 - 10.9.5. | 0.0.0 - 10.9.511.0.0-alpha.1 - 11.14.0 | Medium |
CVE-2026-41150 mermaid is vulnerable to Loop with Unreachable Exit Condition ('Infinite Loop') in versions 11.0.0-alpha.1 - 11.14.0 and 0.0.0 - 10.9.5. | 0.0.0 - 10.9.511.0.0-alpha.1 - 11.14.0 | Medium |
CVE-2026-41149 mermaid is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 11.0.0-alpha.1 - 11.14.0 and 0.0.0 - 10.9.5. | 0.0.0 - 10.9.511.0.0-alpha.1 - 11.14.0 | Medium |
CVE-2026-41148 mermaid is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 11.0.0-alpha.1 - 11.14.0 and 0.0.0 - 10.9.5. | 0.0.0 - 10.9.511.0.0-alpha.1 - 11.14.0 | Medium |
CVE-2025-54881 mermaid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 11.0.0-alpha.1 - 11.10.0 and 10.9.0-rc.1 - 10.9.4. | 10.9.0-rc.1 - 10.9.411.0.0-alpha.1 - 11.10.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
d3 Version ^7.9.0 | — | — |
uuid Version ^11.1.0 || ^12 || ^13 || ^14.0.0 | — | — |
dayjs Version ^1.11.19 | — | — |
katex Version ^0.16.25 | — | — |
khroma Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant