THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3rrr-jr9j-h3q3 (medium) — Mermaid Architecture diagrams are vulnerable to prototype pollution

[GHSA] GHSA-3rrr-jr9j-h3q3 (medium) — Mermaid Architecture diagrams are vulnerable to prototype pollution

highgithub_advisoriesPublished 2026-08-06

GHSA-3rrr-jr9j-h3q3 Severity: medium CVE: CVE-2026-71437

Mermaid Architecture diagrams are vulnerable to prototype pollution

Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent.

### Impact

Any code in the same realm that r

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3rrr-jr9j-h3q3