{"api_version":"v1","generated_at":"2026-10-10T02:15:00+00:00","product":{"cve_count":13,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-mermaid-js-mermaid-81123e87ec57","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/mermaid","name":"mermaid","next_cursor":null,"observations":[{"affected":">= 11.6.0, < 11.16.1","affected_versions_present":true,"cve_id":"CVE-2026-71439","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71439","fixed":"11.16.1.","last_modified":"2026-08-07T17:09:23.203Z","patch_url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh","primary_source":"","published":"2026-08-06T20:01:04.423Z"},{"affected":"< 10.9.8; >= 11.0.0-alpha.1, < 11.16.1","affected_versions_present":true,"cve_id":"CVE-2026-71438","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71438","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T15:40:29.335Z","patch_url":"","primary_source":"","published":"2026-08-06T19:59:07.450Z"},{"affected":"< 10.9.8; >= 11.0.0-alpha.1, < 11.16.1","affected_versions_present":true,"cve_id":"CVE-2026-50159","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50159","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T17:18:23.685Z","patch_url":"","primary_source":"","published":"2026-08-06T19:55:27.994Z"},{"affected":">= 11.5.0, < 11.16.1","affected_versions_present":true,"cve_id":"CVE-2026-71437","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71437","fixed":"11.16.1.","last_modified":"2026-08-07T17:37:35.933Z","patch_url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-3rrr-jr9j-h3q3","primary_source":"","published":"2026-08-06T19:51:52.975Z"},{"affected":">= 10.6.0, < 10.9.8; >= 11.0.0-alpha.1, < 11.16.1","affected_versions_present":true,"cve_id":"CVE-2026-71436","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71436","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-07T16:17:15.115Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-71436","primary_source":"","published":"2026-08-06T19:49:44.739Z"},{"affected":">= 11.0.0-alpha.1, < 11.15.0; < 10.9.6","affected_versions_present":true,"cve_id":"CVE-2026-41150","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41150","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-29T16:17:31.324Z","patch_url":"https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6","primary_source":"","published":"2026-05-29T13:54:52.157Z"},{"affected":">= 11.0.0-alpha.1, < 11.15.0; < 10.9.6","affected_versions_present":true,"cve_id":"CVE-2026-41159","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41159","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-01T19:21:36.047Z","patch_url":"","primary_source":"","published":"2026-05-29T13:53:10.148Z"},{"affected":">= 11.0.0-alpha.1, < 11.15.0; < 10.9.6","affected_versions_present":true,"cve_id":"CVE-2026-41149","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41149","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-23T03:22:44.013Z","patch_url":"","primary_source":"","published":"2026-05-22T22:34:36.944Z"},{"affected":">= 11.0.0-alpha.1, < 11.15.0; < 10.9.6","affected_versions_present":true,"cve_id":"CVE-2026-41148","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41148","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T13:25:35.445Z","patch_url":"","primary_source":"","published":"2026-05-22T22:03:50.872Z"},{"affected":">= 10.9.0-rc.1, <= 11.9.0","affected_versions_present":true,"cve_id":"CVE-2025-54881","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54881","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-08-19T18:14:04.599Z","patch_url":"","primary_source":"","published":"2025-08-19T17:04:29.453Z"},{"affected":">= 11.1.0, < 11.10.0","affected_versions_present":true,"cve_id":"CVE-2025-54880","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54880","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-08-19T17:09:32.759Z","patch_url":"https://github.com/mermaid-js/mermaid/security/advisories/GHSA-8gwm-58g9-j8pw","primary_source":"","published":"2025-08-19T16:58:41.120Z"},{"affected":">= 8.0.0, < 9.1.3","affected_versions_present":true,"cve_id":"CVE-2022-31108","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31108","fixed":"9.1.3.","last_modified":"2025-04-22T17:52:58.513Z","patch_url":"https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225","primary_source":"","published":"2022-06-28T18:35:11.000Z"},{"affected":"< 8.13.8","affected_versions_present":true,"cve_id":"CVE-2021-43861","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43861","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:10:17.137Z","patch_url":"https://github.com/mermaid-js/mermaid/commit/066b7a0d0bda274d94a2f2d21e4323dab5776d83","primary_source":"","published":"2021-12-30T13:40:11.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"mermaid-js"}}
