[Git][security-tracker-team/security-tracker][master] Add some new node-mermaid issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 7 08:49:30 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d791d2de by Salvatore Bonaccorso at 2026-08-07T09:49:10+02:00
Add some new node-mermaid issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35,13 +35,25 @@ CVE-2026-71446 (AIL Framework contains a stored cross-site scripting vulnerabili
 CVE-2026-71445 (AIL Framework contained a reflected cross-site scripting vulnerability ...)
 	NOT-FOR-US: AIL framework
 CVE-2026-71439 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	TODO: check
+	- node-mermaid <unfixed>
+	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e (mermaid at 11.16.1)
+	TODO: check introducing commit, might then be only 11.6.0 and above.
 CVE-2026-71438 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	TODO: check
+	- node-mermaid <unfixed>
+	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-c4c3-pg64-4m4v
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/2cd6dcf735533b323507e3e889ffdea870540b43 (mermaid at 11.16.1)
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/c34b07a0815842327e70794d69b0c8c5a1e2a956 (v10.9.7)
 CVE-2026-71437 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	TODO: check
+	- node-mermaid <unfixed>
+	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/99af3fc35ef0a9a9c8c6314521344d67523ddccf (mermaid at 11.16.1)
+	TODO: check introducing commit for further assessment
 CVE-2026-71436 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	TODO: check
+	- node-mermaid <unfixed>
+	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 (mermaid at 11.16.1)
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a (v10.9.7)
 CVE-2026-71435 (Statamic is a Laravel and Git powered content management system (CMS). ...)
 	NOT-FOR-US: Statamic CMS
 CVE-2026-71434 (Statamic is a Laravel and Git powered content management system (CMS). ...)
@@ -198,7 +210,10 @@ CVE-2026-50515 (Deserialization of untrusted data in Azure Service Bus allows an
 CVE-2026-50481 (Modification of assumed-immutable data (maid) in Azure Active Director ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-50159 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	TODO: check
+	- node-mermaid <unfixed>
+	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6x64-9x62-f2gx
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/12d472c9ed43f94814b110da8d7a9ae6dd5266ed (mermaid at 11.16.1)
+	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/7e83f1533318b307764d961906a73377266f4c5e (v10.9.7)
 CVE-2026-49746 (Software installed and run as a non-privileged user may conduct improp ...)
 	NOT-FOR-US: Imagination Technologies
 CVE-2026-49391 (Frappe is a full-stack web application framework. Prior to 16.19.0 and ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d791d2de7b9167b92d90d16e73d98f877c9724ca

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d791d2de7b9167b92d90d16e73d98f877c9724ca
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/757c1595/attachment.htm>


More information about the debian-security-tracker-commits mailing list