Prototype pollution in mermaid - #VU140932

 

Prototype pollution in mermaid - #VU140932

Published: August 4, 2026


Vulnerability identifier: #VU140932
CSH Severity: High
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service or corrupt application logic.

The vulnerability exists due to improperly controlled modification of object prototype attributes ('prototype pollution') in the architecture-beta diagram renderer when rendering an untrusted diagram. A remote user can supply a crafted diagram with a group id of __proto__ to cause a denial of service or corrupt application logic.

The injected property value is limited to the string horizontal or vertical and does not directly enable remote code execution.


Affected software

mermaid

Remediation

Install security update from vendor's website.

mermaid - update to 11.16.1

External References