mermaid has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was August 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Weakness classes
Products
- mermaid 5
Worst active — by depth score
CVE-2026-71436Medium· 7.5Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts41CVE-2026-71439MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts28CVE-2026-71437MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts28CVE-2026-50159MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts28CVE-2026-71438LowMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts14
mermaid vulnerabilities
CVEs affecting mermaid, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-71436Medium· 7.5Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisR…
CVE-2026-71437MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group…
CVE-2026-50159MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied …
CVE-2026-71438LowMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConf…
CVE-2026-71439MediumMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high …