Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c3864ac5 by Salvatore Bonaccorso at 2026-07-18T06:59:17+02:00
Update node-mermaid issues, it got re-introduced into unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -34556,13 +34556,13 @@ CVE-2026-42941 (TheDanelec MacGregor Voyage Data 
Recorder  device includes a def
 CVE-2026-42929 (Danelec MacGregor Voyage Data Recorder includes default 
accounts with  ...)
        NOT-FOR-US: Danelec
 CVE-2026-41159 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p
        NOTE: 
https://github.com/mermaid-js/mermaid/commit/64769738d5b59211e1decb471ffbaca8afec51aa
 ([email protected])
        NOTE: 
https://github.com/mermaid-js/mermaid/commit/a9d9f0d8eb790349121508688cd338253fd80d76
 (v10.9.6)
 CVE-2026-41150 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
        NOTE: 
https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e
 ([email protected])
@@ -40891,13 +40891,13 @@ CVE-2026-42901 (Origin validation error in Microsoft 
Entra ID allows an unauthor
 CVE-2026-42827 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-41149 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr
        NOTE: Fixed by: 
https://github.com/mermaid-js/mermaid/commit/37ff937f1da2e19f882fd1db01235db4d01f4056
 ([email protected])
        NOTE: Fixed by: 
https://github.com/mermaid-js/mermaid/commit/4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3
 (v10.9.6)
 CVE-2026-41148 (Mermaid is a JavaScript tool that uses Markdown-inspired text 
to creat ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <postponed> (Minor issue, no rdeps)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r
        NOTE: Fixed by: 
https://github.com/mermaid-js/mermaid/commit/e9b0f34d8d82a6260077764ee45e1d7d90957a0f
 ([email protected])
@@ -163281,11 +163281,11 @@ CVE-2025-55294 (screenshot-desktop allows capturing 
a screenshot of your local m
 CVE-2025-55153
        REJECTED
 CVE-2025-54881 (Mermaid is a JavaScript based diagramming and charting tool 
that uses  ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-7rqq-prvp-x9jh
 CVE-2025-54880 (Mermaid is a JavaScript based diagramming and charting tool 
that uses  ...)
-       - node-mermaid <removed>
+       - node-mermaid <unfixed>
        [bullseye] - node-mermaid <not-affected> (Vulnerable code not present)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-8gwm-58g9-j8pw
 CVE-2025-54411 (Discourse is an open-source discussion platform. Welcome 
banner user n ...)
@@ -389794,7 +389794,7 @@ CVE-2023-0993 (The Shield Security plugin for 
WordPress is vulnerable to Missing
 CVE-2023-0992 (The Shield Security plugin for WordPress is vulnerable to 
stored Cross ...)
        NOT-FOR-US: WordPress plugin
 CVE-2022-48345 (sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows 
XSS via ...)
-       - node-mermaid <removed> (bug #1032313)
+       - node-mermaid <unfixed> (bug #1032313)
        [bullseye] - node-mermaid <no-dsa> (Minor issue)
        NOTE: 
https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c
 CVE-2023-26464 (** UNSUPPORTED WHEN ASSIGNED **  When using the Chainsaw or 
SocketAppe ...)
@@ -455755,7 +455755,7 @@ CVE-2022-31110 (RSSHub is an open source, extensible 
RSS feed generator. In comm
 CVE-2022-31109 (laminas-diactoros is a PHP package containing implementations 
of the P ...)
        NOT-FOR-US: laminas-diactoros
 CVE-2022-31108 (Mermaid is a JavaScript based diagramming and charting tool 
that uses  ...)
-       - node-mermaid <removed> (bug #1014540)
+       - node-mermaid 9.2.2+~2.0.0-1 (bug #1014540)
        [bullseye] - node-mermaid <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-x3vm-38hw-55wf
        NOTE: 
https://github.com/mermaid-js/mermaid/commit/0ae1bdb61adff1cd485caff8c62ec6b8ac57b225



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3864ac5564494045be0632037f1648c3f03d253

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3864ac5564494045be0632037f1648c3f03d253
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to