Prototype pollution in mermaid - #VU140932
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service or corrupt application logic.
The vulnerability exists due to improperly controlled modification of object prototype attributes ('prototype pollution') in the architecture-beta diagram renderer when rendering an untrusted diagram. A remote user can supply a crafted diagram with a group id of __proto__ to cause a denial of service or corrupt application logic.
The injected property value is limited to the string horizontal or vertical and does not directly enable remote code execution.