Bug 2512224 (CVE-2026-71437) - CVE-2026-71437 mermaid: Mermaid: Prototype pollution vulnerability allows potential arbitrary code execution
Summary: CVE-2026-71437 mermaid: Mermaid: Prototype pollution vulnerability allows pot...
Keywords:
Status: NEW
Alias: CVE-2026-71437
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2512869 2512870 2512871 2512872 2512873 2512874 2512875 2512876 2512877 2512878 2512879 2512880
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 22:23 UTC by OSIDB Bzimport
Modified: 2026-08-09 07:16 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 22:23:15 UTC
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group with an id of __proto__. Because the group id is used directly as an object property key without validation, an attacker who can supply diagram text can pollute Object.prototype, potentially affecting the behavior of the embedding application. This issue is fixed in version 11.16.1.


Note You need to log in before you can comment on or make changes to this bug.