CVE-2025-54880 | mermaid-js mermaid up to 11.9.x html cross site scripting (Nessus ID 264684)
A vulnerability categorized as problematic has been discovered in mermaid-js mermaid up to 11.9.x. The impacted element is the function html. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2025-54880. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.