mermaid
npmlibrary
Overview
Canonical component data stored by Polaris.
Version
11.16.0
Package Manager
npm
Type
library
Systems
1
Licenses
MIT
Direct Dependencies
24
Technology
Not linked
External Signals
deps.dev endoflife.date OSV.dev
Package URL
pkg:npm/[email protected]
Maintenance
Derived from available component and registry data
Confidence
Medium
Version Age
102 days
Update Status
Major update available
Recent Activity
Yes
Reasons
Recent versionMature versionMajor available
Lifecycle
Source: endoflife.date
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Registry
Source: deps.dev
Ecosystem
npm
Latest Version
12.1.0
Published
6/25/2026
Recent Releases
16
Advisories
5
Advisory Links
Open deps.devKnown Vulnerabilities
Source: OSV.dev
GHSA-2v8p-3f2j-5mp7
Mermaid XY Charts are vulnerable to an infinite loop DoS
Affected Versions
Open advisory>= 10.6.0, before 10.9.8>= 11.0.0-alpha.1, before 11.16.1
GHSA-3rrr-jr9j-h3q3
Mermaid Architecture diagrams are vulnerable to prototype pollution
Affected Versions
Open advisory>= 11.5.0, before 11.16.1
GHSA-6x64-9x62-f2gx
Mermaid allows CSS injection applying to sibling elements of the diagram
Affected Versions
Open advisory>= 11.0.0-alpha.1, before 11.16.1all versions before 10.9.8
GHSA-c4c3-pg64-4m4v
Mermaid configuration APIs allow prototype pollution
Affected Versions
Open advisory>= 11.0.0-alpha.1, before 11.16.1all versions before 10.9.8
GHSA-rhh3-jpg6-66xh
Mermaid radar diagrams are vulnerable to DoS
Affected Versions
Open advisory>= 11.6.0, before 11.16.1
Security
Source: OpenSSF Scorecard
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.
Systems (1)
Dependencies
24 direct dependencies