[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for node-mermaid issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 09:43:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a78a91f9 by Salvatore Bonaccorso at 2026-07-20T10:43:01+02:00
Add Debian bug reference for node-mermaid issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37720,13 +37720,13 @@ CVE-2026-42941 (TheDanelec MacGregor Voyage Data Recorder  device includes a def
 CVE-2026-42929 (Danelec MacGregor Voyage Data Recorder includes default accounts with  ...)
 	NOT-FOR-US: Danelec
 CVE-2026-41159 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1142457)
 	[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p
 	NOTE: https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa (mermaid at 11.15.0)
 	NOTE: https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76 (v10.9.6)
 CVE-2026-41150 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1142457)
 	[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
 	NOTE: https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e (mermaid at 11.15.0)
@@ -44055,13 +44055,13 @@ CVE-2026-42901 (Origin validation error in Microsoft Entra ID allows an unauthor
 CVE-2026-42827 (Improper neutralization of special elements used in a command ('comman ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-41149 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1142457)
 	[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056 (mermaid at 11.15.0)
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3 (v10.9.6)
 CVE-2026-41148 (Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...)
-	- node-mermaid <unfixed>
+	- node-mermaid <unfixed> (bug #1142457)
 	[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
 	NOTE: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r
 	NOTE: Fixed by: https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f (mermaid at 11.15.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a78a91f956c6ad403f64827c0728ab57cda7ea26

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a78a91f956c6ad403f64827c0728ab57cda7ea26
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/eb9ed80a/attachment.htm>


More information about the debian-security-tracker-commits mailing list