Skip to content

Security issues raised by lodash-es #7345

@theniceangel

Description

@theniceangel

Description

Path: mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->lodash-es-4.17.21.tgz
lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-allstar-0.3.1.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->dagre-d3-es-7.0.13.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->cst-dts-gen-11.0.3.tgz->lodash-es-4.17.21.tgz
mermaid-11.12.1.tgz->parser-0.6.3.tgz->langium-3.3.1.tgz->chevrotain-11.0.3.tgz->gast-11.0.3.tgz->lodash-es-4.17.21.tgz

CRITICAL: CVE-2025-13465

lodash-es should bump to 4.17.23

Steps to reproduce

install @mermaid-js/parser@0.6.3 or @mermaid-js/parser@latest

Screenshots

No response

Code Sample


Setup

  • Mermaid version:
  • Browser and Version: [Chrome, Edge, Firefox]

Suggested Solutions

No response

Additional Context

No response

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions