Bug 2480858 (CVE-2026-41148)
| Summary: | CVE-2026-41148 mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | cdrage, jkoehler, lphiri, rushinde |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Mermaid, a JavaScript tool used for creating diagrams. This vulnerability, identified as a CSS injection, allows a remote attacker to inject arbitrary CSS rules due to improper sanitization of user-controlled style strings. By exploiting an unrestricted regular expression in the state diagram parser, an attacker can terminate generated CSS selectors and create new CSS rules. This can lead to page defacement, user tracking through URL (Uniform Resource Locator) callbacks, and exfiltration of Document Object Model (DOM) attributes.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2489148, 2489150, 2489155, 2489156, 2489158, 2489160, 2489162, 2489147, 2489149, 2489151, 2489152, 2489153, 2489154, 2489157, 2489159, 2489161 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-22 23:01:20 UTC
|