GHSA-4gpc-rhpj-9443
CRITICALCVE-2026-23733A stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE).
- Affected
- <= 1.143.2
- Fixed in
- not stated
- Weakness
- CWE-94
- Published
- 2026-01-20
- Source
- github