CVE-2026-71438Low▾ SunlitMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConf…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
0.2% → 0.2%
Last analysed / modified upstream
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration into Mermaid's internal config using the assignWithDepth deep-merge helper, which is vulnerable to prototype pollution. This is only exploitable if an application forwards untrusted data directly into one of these configuration entry points, which is outside their documented usage; diagram-supplied configuration (e.g. %%{init: {}}%% or YAML frontmatter) is not affected. This issue is fixed in versions 10.9.8 and 11.16.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
mermaid >= 11.0.0-alpha.1, < 11.16.1mermaid < 10.9.8Patched in:
mermaid 11.16.1mermaid 10.9.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71436Medium· 7.5Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
CVE-2026-71437MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
CVE-2026-50159MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
CVE-2026-71439MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
CVE-2026-61534Critical· 9.1Yayson is a library for serializing and reading JSON API data in JavaScript
CVE-2026-86078Medium· 6.5n8n is an open source workflow automation platform