<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:21:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-250165</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-250165</link>
      <description>EUVD-2026-250165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-250165</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54881</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54881</link>
      <description>&lt;p&gt;Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54881</guid>
    </item>
    <item>
      <title>GHSA-7rqq-prvp-x9jh — Mermaid improperly sanitizes sequence diagram labels leading to XSS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7rqq-prvp-x9jh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mermaid&lt;/p&gt;
&lt;p&gt;### Summary
In the default configuration of mermaid 11.9.0, user supplied input for sequence diagram labels is passed to `innerHTML` during calculation of element size, causing XSS.&lt;/p&gt;
&lt;p&gt;### Details
Sequence diagram node labels with KaTeX delimiters are passed through `calculateMathMLDimensions`. This method passes the full label to `innerHTML` which allows allows malicious users to inject arbitrary HTML and cause XSS when mermaid-js is used in it&amp;#39;s default configuration (with KaTeX support enabled).&lt;/p&gt;
&lt;p&gt;The vulnerability lies here:&lt;/p&gt;
&lt;p&gt;```ts
export const calculateMathMLDimensions = async (text: string, config: MermaidConfig) =&amp;gt; {
  text = await renderKatex(text, config);
  const divElem = document.createElement(&amp;#39;div&amp;#39;);
  divElem.innerHTML = text; // XSS sink, text has not been sanitized.
  divElem.id = &amp;#39;katex-temp&amp;#39;;
  divElem.style.visibility = &amp;#39;hidden&amp;#39;;
  divElem.style.position = &amp;#39;absolute&amp;#39;;
  divElem.style.top = &amp;#39;0&amp;#39;;
  const body = document.querySelector(&amp;#39;body&amp;#39;);
  body?.insertAdjacentElement(&amp;#39;beforeend&amp;#39;, divElem);
  const dim = { width: divElem.clientWidth, height: divElem.clientHeight };
  divElem.remove();
  return dim;
};
```&lt;/p&gt;
&lt;p&gt;The `calculateMathMLDimensions` method was introduced in 5c69e5fdb004a6d0a2abe97e23d26e223a059832 two years ago, which was released in [Mermaid 10.9.0](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.0).&lt;/p&gt;
&lt;p&gt;### PoC
Render the following diagram and observe the modified DOM.&lt;/p&gt;
&lt;p&gt;```
sequenceDiagram
    participant A as Alice&amp;lt;img src=&amp;#34;x&amp;#34; onerror=&amp;#34;docume…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: mermaid&lt;/p&gt;
&lt;p&gt;### Summary
In the default configuration of mermaid 11.9.0, user supplied input for sequence diagram labels is passed to `innerHTML` during calculation of element size, causing XSS.&lt;/p&gt;
&lt;p&gt;### Details
Sequence diagram node labels with KaTeX delimiters are passed through `calculateMathMLDimensions`. This method passes the full label to `innerHTML` which allows allows malicious users to inject arbitrary HTML and cause XSS when mermaid-js is used in it&amp;#39;s default configuration (with KaTeX support enabled).&lt;/p&gt;
&lt;p&gt;The vulnerability lies here:&lt;/p&gt;
&lt;p&gt;```ts
export const calculateMathMLDimensions = async (text: string, config: MermaidConfig) =&amp;gt; {
  text = await renderKatex(text, config);
  const divElem = document.createElement(&amp;#39;div&amp;#39;);
  divElem.innerHTML = text; // XSS sink, text has not been sanitized.
  divElem.id = &amp;#39;katex-temp&amp;#39;;
  divElem.style.visibility = &amp;#39;hidden&amp;#39;;
  divElem.style.position = &amp;#39;absolute&amp;#39;;
  divElem.style.top = &amp;#39;0&amp;#39;;
  const body = document.querySelector(&amp;#39;body&amp;#39;);
  body?.insertAdjacentElement(&amp;#39;beforeend&amp;#39;, divElem);
  const dim = { width: divElem.clientWidth, height: divElem.clientHeight };
  divElem.remove();
  return dim;
};
```&lt;/p&gt;
&lt;p&gt;The `calculateMathMLDimensions` method was introduced in 5c69e5fdb004a6d0a2abe97e23d26e223a059832 two years ago, which was released in [Mermaid 10.9.0](https://github.com/mermaid-js/mermaid/releases/tag/v10.9.0).&lt;/p&gt;
&lt;p&gt;### PoC
Render the following diagram and observe the modified DOM.&lt;/p&gt;
&lt;p&gt;```
sequenceDiagram
    participant A as Alice&amp;lt;img src=&amp;#34;x&amp;#34; onerror=&amp;#34;docume…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7rqq-prvp-x9jh</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-54881</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54881</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-mermaid&lt;/p&gt;
&lt;p&gt;Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-mermaid&lt;/p&gt;
&lt;p&gt;Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of element size, causing XSS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54881</guid>
    </item>
  </channel>
</rss>
