CVE-2026-40322: Mermaid Svg Innerhtml Xss Without Dompurify
Mermaid SVG output from `$MERMAID.render()` is inserted into `innerHTML` without DOMPurify sanitization. Mermaid diagrams rendered with securityLevel "loose" allow attacker-controlled HTML/JavaScript to survive into the SVG output (via inline event handlers such as onerror/onload, <script> elements, or javascript: URLs in href attributes). The regex-only app
greprules fetch cve-2026-40322-mermaid-svg-innerhtml-xss-without-dompurify --engine opengrepDescription
Mermaid SVG output from `$MERMAID.render()` is inserted into `innerHTML` without DOMPurify sanitization. Mermaid diagrams rendered with securityLevel "loose" allow attacker-controlled HTML/JavaScript to survive into the SVG output (via inline event handlers such as onerror/onload, <script> elements, or javascript: URLs in href attributes). The regex-only app
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.