SCA: security update for mermaid (GHSA-2v8p-3f2j-5mp7)

medium Tenable Cloud Security Plugin ID 445759

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts.
From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial
of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because
each loop iteration appends an element to an array, this generally causes a RangeError to appear after a
few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion,
depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1. (CVE-2026-71436)

Solution

Update the mermaid library and its related packages to version 10.9.8 or later.

See Also

https://github.com/advisories/GHSA-2v8p-3f2j-5mp7

Plugin Details

Severity: Medium

ID: 445759

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/7/2026

Updated: 8/7/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-71436

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 5.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-71436