THREAT OPS › Threat News › [GHSA] GHSA-c4c3-pg64-4m4v (low) — Mermaid configuration APIs allow prototype pollution
[GHSA] GHSA-c4c3-pg64-4m4v (low) — Mermaid configuration APIs allow prototype pollution
GHSA-c4c3-pg64-4m4v Severity: low CVE: CVE-2026-71438
Mermaid configuration APIs allow prototype pollution
### Summary
Mermaid's configuration setters (`mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig`) merge the caller-supplied configuration object into Mermaid's internal config using the `assignWithDepth` deep-merge helper that is vulnerable to prototype pollutio
Indicators of compromise
- 2cd6dcf735533b323507e3e889ffdea870540b43sha1
- c34b07a0815842327e70794d69b0c8c5a1e2a956sha1
- CVE-2026-71438cve
- https://lzhou1110.github.io/url
- https://zyy0530.github.io/url
- https://str1ckl4nd.github.io/url
- http://maurice.busystar.org/url
- https://7thparkk.github.io/url
- liyi.zhou@sydney.edu.auemail
- ziyue0530@gmail.comemail
- cshe0476@uni.sydney.edu.auemail
- chng0012@uni.sydney.edu.auemail
- cyu210608@gmail.comemail
Original source: https://github.com/advisories/GHSA-c4c3-pg64-4m4v