| Bug | bullseye | Description |
|---|
| CVE-2026-41159 | vulnerable (no DSA, postponed) | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... |
| CVE-2026-41150 | vulnerable (no DSA, postponed) | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... |
| CVE-2026-41149 | vulnerable (no DSA, postponed) | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... |
| CVE-2026-41148 | vulnerable (no DSA, postponed) | Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ... |
| CVE-2022-48345 | vulnerable (no DSA) | sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via ... |
| CVE-2022-31108 | vulnerable (no DSA) | Mermaid is a JavaScript based diagramming and charting tool that uses ... |