CVE Database
/

CVE-2026-41150

Back to search

CVE-2026-41150

Published: May 29, 2026

Modified: May 29, 2026

PUBLISHED

Description

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.

VendorProductVersions

mermaid-js

mermaid

affected
>= 11.0.0-alpha.1, < 11.15.0
affected
< 10.9.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now