Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c3864ac5 by Salvatore Bonaccorso at 2026-07-18T06:59:17+02:00
Update node-mermaid issues, it got re-introduced into unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -34556,13 +34556,13 @@ CVE-2026-42941 (TheDanelec MacGregor Voyage Data
Recorder device includes a def
CVE-2026-42929 (Danelec MacGregor Voyage Data Recorder includes default
accounts with ...)
NOT-FOR-US: Danelec
CVE-2026-41159 (Mermaid is a JavaScript tool that uses Markdown-inspired text
to creat ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p
NOTE:
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa
([email protected])
NOTE:
https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
(v10.9.6)
CVE-2026-41150 (Mermaid is a JavaScript tool that uses Markdown-inspired text
to creat ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
NOTE:
https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e
([email protected])
@@ -40891,13 +40891,13 @@ CVE-2026-42901 (Origin validation error in Microsoft
Entra ID allows an unauthor
CVE-2026-42827 (Improper neutralization of special elements used in a command
('comman ...)
NOT-FOR-US: Microsoft
CVE-2026-41149 (Mermaid is a JavaScript tool that uses Markdown-inspired text
to creat ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr
NOTE: Fixed by:
https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056
([email protected])
NOTE: Fixed by:
https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3
(v10.9.6)
CVE-2026-41148 (Mermaid is a JavaScript tool that uses Markdown-inspired text
to creat ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r
NOTE: Fixed by:
https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f
([email protected])
@@ -163281,11 +163281,11 @@ CVE-2025-55294 (screenshot-desktop allows capturing
a screenshot of your local m
CVE-2025-55153
REJECTED
CVE-2025-54881 (Mermaid is a JavaScript based diagramming and charting tool
that uses ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh
CVE-2025-54880 (Mermaid is a JavaScript based diagramming and charting tool
that uses ...)
- - node-mermaid <removed>
+ - node-mermaid <unfixed>
[bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-8gwm-58g9-j8pw
CVE-2025-54411 (Discourse is an open-source discussion platform. Welcome
banner user n ...)
@@ -389794,7 +389794,7 @@ CVE-2023-0993 (The Shield Security plugin for
WordPress is vulnerable to Missing
CVE-2023-0992 (The Shield Security plugin for WordPress is vulnerable to
stored Cross ...)
NOT-FOR-US: WordPress plugin
CVE-2022-48345 (sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows
XSS via ...)
- - node-mermaid <removed> (bug #1032313)
+ - node-mermaid <unfixed> (bug #1032313)
[bullseye] - node-mermaid <no-dsa> (Minor issue)
NOTE:
https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c
CVE-2023-26464 (** UNSUPPORTED WHEN ASSIGNED ** When using the Chainsaw or
SocketAppe ...)
@@ -455755,7 +455755,7 @@ CVE-2022-31110 (RSSHub is an open source, extensible
RSS feed generator. In comm
CVE-2022-31109 (laminas-diactoros is a PHP package containing implementations
of the P ...)
NOT-FOR-US: laminas-diactoros
CVE-2022-31108 (Mermaid is a JavaScript based diagramming and charting tool
that uses ...)
- - node-mermaid <removed> (bug #1014540)
+ - node-mermaid 9.2.2+~2.0.0-1 (bug #1014540)
[bullseye] - node-mermaid <no-dsa> (Minor issue)
NOTE:
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-x3vm-38hw-55wf
NOTE:
https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3864ac5564494045be0632037f1648c3f03d253
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3864ac5564494045be0632037f1648c3f03d253
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits