Prototype pollution in mermaid - CVE-2026-71437
Published: August 4, 2026 / Updated: August 7, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service or corrupt application logic.
The vulnerability exists due to improperly controlled modification of object prototype attributes ('prototype pollution') in the architecture-beta diagram renderer when rendering an untrusted diagram. A remote user can supply a crafted diagram with a group id of __proto__ to cause a denial of service or corrupt application logic.
The injected property value is limited to the string horizontal or vertical and does not directly enable remote code execution.
Affected software
Fedora
nextcloud
How to mitigate CVE-2026-71437
nextcloud - addressed in versions 34.0.3-1.el10_2, 34.0.3-1.el10_3, 34.0.3-1.fc44