CVE-2021-35513Cross-site Scripting in Project Mermaid

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateDec 10

Description

Mermaid before 8.11.0 allows XSS when the antiscript feature is used.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

debiandebian/node-mermaid< node-mermaid 8.7.0+ds+~cs27.17.17-3 (bullseye)

Patches

🔴Vulnerability Details

3
GHSA
Cross-site Scripting in Mermaid2021-12-10
OSV
Cross-site Scripting in Mermaid2021-12-10
OSV
CVE-2021-35513: Mermaid before 82021-06-27

📋Vendor Advisories

1
Debian
CVE-2021-35513: node-mermaid - Mermaid before 8.11.0 allows XSS when the antiscript feature is used.2021