fig. 01 — CVE-2025-54880, the advisory selected below
// advisories
CVE-2025-54880
MODERATE
In the default configuration of mermaid 11.9.0, user supplied input for architecture diagram icons is passed to the d3 html() method, creating a sink for cross site scripting.