CVE-2026-71438 | mermaid-js Mermaid up to 10.9.7/11.16.0 Configuration Merge Helper prototype pollution

SecurityVulns

A vulnerability described as critical has been identified in mermaid-js Mermaid up to 10.9.7/11.16.0. Affected is the function mermaid.initialize/mermaidAPI.setConfig/mermaidAPI.updateSiteConfig of the component Configuration Merge Helper. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.

This vulnerability is tracked as CVE-2026-71438. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More