Executive brief
Mermaid is a popular library used to generate charts and diagrams from text. A vulnerability in how it handles state diagrams allows an attacker to inject malicious HTML code into a page. While the library attempts to block scripts, an attacker could still alter the visual appearance of the page or overlay fake content to deceive users.
Technical details
An HTML injection vulnerability exists in Mermaid's state diagram implementation due to improper sanitization of the `classDef` directive. By crafting a specific diagram string, an attacker can use CSS and HTML tags to escape the SVG container and inject arbitrary DOM elements into the host page. While Mermaid's default configuration removes `<script>` tags (preventing direct XSS), an attacker can still perform UI redressing or CSS-based attacks. The vulnerability is exploitable if a user views a diagram containing malicious `classDef` definitions. Patches are available in versions 11.15.0 and 10.9.6; a workaround is to set `securityLevel` to `sandbox`.
Affected products
- mermaid-js mermaid >= 11.0.0-alpha.1, <= 11.14.0
- mermaid-js mermaid <= 10.9.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: advisory
- 2026-05-11: patched