CVE-2026-71437: Mermaid Architecture diagrams are vulnerable to prototype pollution
Rendering an untrusted architecture-beta diagram lets the diagram author write an arbitrary property with the value horizontal or vertical onto Object.prototype. A group id of __proto__ is accepted as a valid parent.
References
- github.com/advisories/GHSA-3rrr-jr9j-h3q3
- github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf
- github.com/mermaid-js/mermaid/pull/8022
- github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1
- github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3
- nvd.nist.gov/vuln/detail/CVE-2026-71437
Code Behaviors & Features
Detect and mitigate CVE-2026-71437 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →