OSV 1.4.0 · github-reviewed · 修改于 2021-09-27 21:34
发布时间
2020-09-02 23:41
GitHub 审查时间
2020-09-01 02:34
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-w32g-5hqp-gg6q/GHSA-w32g-5hqp-gg6q.json
Versions of mermaid prior to 8.2.3 are vulnerable to Cross-Site Scripting. If malicious input such as A["<img src=invalid onerror=alert('XSS')></img>"] is provided to the application, it will execute the code instead of rendering it as text due to improper output encoding.
Upgrade to version 8.2.3 or later