These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-71439 debrief based on CVE Program and NVD records. The vulnerability affects Mermaid Radar Diagrams, allowing arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process. Defenders should assess exposure and verify if Mermaid version is 11.16.1 or later. This issue is fixed in version 11.16.1. The CVE record and NVD entry [truncated]
CVE-2026-71438 is a low-severity vulnerability in the Mermaid JavaScript tool, which can lead to prototype pollution if untrusted data is directly forwarded into specific configuration entry points. This issue, fixed in versions 10.9.8 and 11.16.1, primarily affects applications using Mermaid's configuration setters with untrusted input. The vulnerability arises from the assignWithDepth deep-merge helper [truncated]
CVE-2026-71437 is a vulnerability in Mermaid, a JavaScript tool for creating diagrams and charts. From version 11.5.0 to 11.16.1, Mermaid's Architecture Diagrams are susceptible to prototype pollution when a diagram defines a group with an id of __proto__. This issue allows an attacker to pollute Object.prototype, potentially affecting the behavior of the embedding application. The vulnerability is fixed [truncated]
CVE-2026-71436 is a denial-of-service vulnerability affecting Mermaid's XY Charts feature. The issue arises from an infinite loop in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. This vulnerability impacts Mermaid versions 10.6.0 through 10.9.8 and 11.16.1. The vulnerability is fixed in versions 10.9.8 and 11.16.1.
CVE-2026-50159 Mermaid CSS Injection Vulnerability: Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1. Mermaid users an [truncated]
CVE-2026-41159 is a CSS injection vulnerability in Mermaid, a JavaScript diagramming library. The issue stems from Mermaid's default configuration allowing untrusted CSS injection through the `fontFamily`, `themeCSS`, and `altFontFamily` configuration options. The vulnerability exploits stylis's `&` (scope reference) handling, where `:not(&)` selectors escape the automatic `#mermaid-xxx` scoping and apply [truncated]
A denial-of-service vulnerability exists in Mermaid, a JavaScript diagramming library, when rendering Gantt charts with the excludes attribute configured to exclude all dates. The issue affects versions prior to 10.9.6 and 11.15.0. While mermaid.parse itself is not directly vulnerable, the ganttDb.getTasks() function—invoked during diagram rendering—triggers the flaw. An attacker could exploit this by sup [truncated]
Mermaid, a JavaScript diagramming library, contains an HTML injection vulnerability in its state diagram classDef directive. Affected versions (10.9.5 and earlier, plus 11.0.0-alpha.1 through 11.14.0) allow DOM injection that escapes the SVG rendering context. While <script> tags are filtered preventing XSS, the injection can still manipulate page structure and potentially enable phishing or UI redressing [truncated]
Mermaid, a JavaScript diagramming library, contains a CSS injection vulnerability in versions 10.9.5 and prior, as well as 11.0.0-alpha.1 through 11.12.0. The flaw exists in the state diagram parser and other diagram types that route user-controlled style strings through createCssStyles. The classDef values are captured using an unrestricted regex matching everything up to a newline, which then flows unsa [truncated]