THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c4c3-pg64-4m4v (low) — Mermaid configuration APIs allow prototype pollution

[GHSA] GHSA-c4c3-pg64-4m4v (low) — Mermaid configuration APIs allow prototype pollution

highgithub_advisoriesPublished 2026-08-06

GHSA-c4c3-pg64-4m4v Severity: low CVE: CVE-2026-71438

Mermaid configuration APIs allow prototype pollution

### Summary

Mermaid's configuration setters (`mermaid.initialize`, `mermaidAPI.setConfig`, and `mermaidAPI.updateSiteConfig`) merge the caller-supplied configuration object into Mermaid's internal config using the `assignWithDepth` deep-merge helper that is vulnerable to prototype pollutio

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c4c3-pg64-4m4v