THREAT OPS › Threat News › [GHSA] GHSA-3rrr-jr9j-h3q3 (medium) — Mermaid Architecture diagrams are vulnerable to prototype pollution
[GHSA] GHSA-3rrr-jr9j-h3q3 (medium) — Mermaid Architecture diagrams are vulnerable to prototype pollution
GHSA-3rrr-jr9j-h3q3 Severity: medium CVE: CVE-2026-71437
Mermaid Architecture diagrams are vulnerable to prototype pollution
Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent.
### Impact
Any code in the same realm that r
Indicators of compromise
- cb0a4703bdf01d47508bde1c08aa9a980d70bc20sha1
- 99af3fc35ef0a9a9c8c6314521344d67523ddccfsha1
- CVE-2026-71437cve
Original source: https://github.com/advisories/GHSA-3rrr-jr9j-h3q3