GHSA-cgmm-x5ww-q5cr
MODERATECVE-2026-26226beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams. User-controlled values from Mermaid style and classDef directives are interpolated into SVG attribute values without proper escaping, allowing crafted input to break out of an attribute context and inject arbitrary SVG e
- Affected
- < 0.1.3
- Fixed in
- 0.1.3
- Weakness
- CWE-79
- Published
- 2026-02-13
- Source
- github