CVE-2026-50159

MEDIUM

Mermaid allows CSS injection applying to sibling elements of the diagram

Title source: cna
STIX 2.1

Description

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

Scores

CVSS v4 5.3
EPSS 0.0057
EPSS Percentile 44.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (4)
mermaid-js/mermaid < 10.9.8
mermaid-js/mermaid >= 11.0.0-alpha.1, < 11.16.1
npm/mermaid 0 - 10.9.8npm
npm/mermaid 11.0.0-alpha.1 - 11.16.1npm
Published Aug 06, 2026
Tracked Since Aug 07, 2026