npmlibrary

Overview

Canonical component data stored by Polaris.

Version

11.16.0

Package Manager

npm

Type

library

Systems

1

Licenses
MIT
Direct Dependencies

24

Technology

Not linked

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:npm/[email protected]

Maintenance

Derived from available component and registry data

Aging
Confidence

Medium

Version Age

102 days

Update Status

Major update available

Recent Activity

Yes

Reasons
Recent versionMature versionMajor available

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Registry

Source: deps.dev

Available
Ecosystem

npm

Latest Version

12.1.0

Published

6/25/2026

Recent Releases

16

Advisories

5

Open deps.dev

Known Vulnerabilities

Source: OSV.dev

5 found

GHSA-2v8p-3f2j-5mp7

Mermaid XY Charts are vulnerable to an infinite loop DoS

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Affected Versions
>= 10.6.0, before 10.9.8>= 11.0.0-alpha.1, before 11.16.1
Open advisory

GHSA-3rrr-jr9j-h3q3

Mermaid Architecture diagrams are vulnerable to prototype pollution

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H
Affected Versions
>= 11.5.0, before 11.16.1
Open advisory

GHSA-6x64-9x62-f2gx

Mermaid allows CSS injection applying to sibling elements of the diagram

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
Affected Versions
>= 11.0.0-alpha.1, before 11.16.1all versions before 10.9.8
Open advisory

GHSA-c4c3-pg64-4m4v

Mermaid configuration APIs allow prototype pollution

CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H
Affected Versions
>= 11.0.0-alpha.1, before 11.16.1all versions before 10.9.8
Open advisory

GHSA-rhh3-jpg6-66xh

Mermaid radar diagrams are vulnerable to DoS

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Affected Versions
>= 11.6.0, before 11.16.1
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

24 direct dependencies

Global view