CVE-2022-46180 Information

Description

Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse open-source forum software to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the main branch of the GitHub repository with 1.1.0 named as a patched version. Admins can update the theme component through the admin UI. As a workaround admins can temporarily disable discourse-mermaid-theme-component.

Reference

https://github.com/discourse/discourse-mermaid-theme-component/commit/c10bc4a08bf865cee20e5d5dffba535762813f0f https://github.com/discourse/discourse-mermaid-theme-component/pull/14 https://github.com/discourse/discourse-mermaid-theme-component/security/advisories/GHSA-8437-hgcm-p3q3

Share on: