mermaid.initialize/mermaidAPI.setConfig/mermaidAPI.updateSiteConfig of the component Configuration Merge Helper. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.This vulnerability is tracked as CVE-2026-71438. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf vuldb.com.
SOCIAL SHARE CARD GENERATOR