Denial-of-Service Vulnerability in Mermaid JavaScript Tool
CVE-2026-41150

5.3MEDIUM

Key Information:

Vendor

Mermaid-js

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-41150?

Mermaid, a popular JavaScript tool for creating diagrams and charts, is susceptible to a denial-of-service vulnerability when rendering gantt charts that utilize the excludes attribute to exclude all dates. This can lead to unexpected behavior, potentially overwhelming system resources. The issue affects versions prior to 10.9.6 and 11.15.0. To mitigate this risk, users should promptly upgrade to the fixed versions to ensure application stability and security. For more details, refer to the GitHub advisory.

Affected Version(s)

mermaid >= 11.0.0-alpha.1, < 11.15.0 < 11.0.0-alpha.1, 11.15.0

mermaid < 10.9.6 < 10.9.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.