[Git][security-tracker-team/security-tracker][master] Update status for node-mermaid issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 18 06:25:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
43744d0a by Salvatore Bonaccorso at 2026-07-18T07:24:56+02:00
Update status for node-mermaid issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -163282,12 +163282,10 @@ CVE-2025-55294 (screenshot-desktop allows capturing a screenshot of your local m
 CVE-2025-55153
 	REJECTED
 CVE-2025-54881 (Mermaid is a JavaScript based diagramming and charting tool that uses  ...)
-	- node-mermaid <unfixed>
-	[bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
+	- node-mermaid <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh
 CVE-2025-54880 (Mermaid is a JavaScript based diagramming and charting tool that uses  ...)
-	- node-mermaid <unfixed>
-	[bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
+	- node-mermaid <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-8gwm-58g9-j8pw
 CVE-2025-54411 (Discourse is an open-source discussion platform. Welcome banner user n ...)
 	NOT-FOR-US: Discourse
@@ -455758,7 +455756,7 @@ CVE-2022-31108 (Mermaid is a JavaScript based diagramming and charting tool that
 	- node-mermaid 9.2.2+~2.0.0-1 (bug #1014540)
 	[bullseye] - node-mermaid <no-dsa> (Minor issue)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-x3vm-38hw-55wf
-	NOTE: https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225
+	NOTE: https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225 (9.1.3)
 CVE-2022-31107 (Grafana is an open-source platform for monitoring and observability. I ...)
 	- grafana <removed>
 CVE-2022-31106 (Underscore.deep is a collection of Underscore mixins that operate on n ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43744d0a16e05edbf9d10ca5857c72cb9aac00e2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43744d0a16e05edbf9d10ca5857c72cb9aac00e2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/b356a44c/attachment.htm>


More information about the debian-security-tracker-commits mailing list