mediumVulnerability

GHSA-39h7-pwv7-rc3x

### Impact `@excalidraw/[email protected]` depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could trigger XSS through Mermaid’s KaTeX label rendering path. This is patched in `@excalidraw/[email protected]` by updating `@excalidraw/mermaid-to-excalidraw` to `2.2.2`, which uses a patched Mermaid 11 release. Moderate severity as this XSS requires manual user action - pasting unsafe Mermaid diagram into the Excalidraw editor. No semi-automated attack vector exists by default (such as accessing a link). ### Patches - Stable `@excalidraw/[email protected]` is patched. - Unstable `@excalidraw/excalidraw@next` has resolved to patched builds since `@excalidraw/[email protected]` on 2025-08-21. - Direct consumers of `@excalidraw/mermaid-to-excalidraw` should use `1.1.3` or later. ### Workarounds None. ### Resources - Upstream Mermaid advisory: https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh - CVE-2025-54881

Properties

ghsa_id
GHSA-39h7-pwv7-rc3x
severity
medium
summary
Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)
cve_id
GHSA-39h7-pwv7-rc3x
is_ghsa_only
true
ghsa_published
2026-04-24T20:41:51Z
source_url
https://github.com/advisories/GHSA-39h7-pwv7-rc3x
ghsa_updated
2026-04-24T20:41:54Z

Related Entities (7)

VULNERABLE_TO (2)

[Software]npm/@excalidraw/mermaid-to-excalidraw
[Software]npm/@excalidraw/excalidraw

AFFECTS (2)

[Software]npm/@excalidraw/excalidraw
[Software]npm/@excalidraw/mermaid-to-excalidraw

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
[Weakness]Dependency on Vulnerable Third-Party Component

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph