Cross-site scripting in mermaid - CVE-2025-54881
Published: September 23, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via diagram labels. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Fedora
jupyterlab
forgejo
nextcloud
How to mitigate CVE-2025-54881
jupyterlab - addressed in versions 4.4.7-1.el10_1, 4.4.7-1.el10_2, 4.4.7-1.fc41, 4.4.7-1.fc42, 4.4.7-1.fc43
forgejo - addressed in versions 12.0.3-1.el10_2, 12.0.3-1.fc42
nextcloud - addressed in versions 31.0.9-1.el10_1, 31.0.9-1.el10_2, 31.0.9-1.fc41, 31.0.9-1.fc42, 31.0.9-1.fc43, 31.0.9-1.fc44
External References
Related Security Bulletins
- Two XSS vulnerabilities in mermaid-js mermaid
- Fedora 43 update for jupyterlab
- Fedora 42 update for jupyterlab
- Fedora 41 update for jupyterlab
- Fedora EPEL 10.2 update for forgejo
- Fedora 42 update for forgejo
- Fedora EPEL 10.1 update for jupyterlab
- Fedora EPEL 10.2 update for jupyterlab
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora 42 update for nextcloud
- Fedora 41 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora EPEL 10.1 update for nextcloud