v10.9.6

withastro/astrov10.9.6May 11, 2026by aloisklink

AI Summary

A security-focused patch release that backports critical fixes from Mermaid v11.15.0 to address vulnerabilities and dependency warnings.

Key Highlights

  • Backported security fixes for Mermaid (CVEs) including loop limits and CSS style handling.
  • Fixed unbalanced CSS styles in classDefs and blocked stylis scope escape.
  • Loosened the uuid dependency range to allow v14 and silence warnings.

Full Release Notes

Backports the following security fixes from [Mermaid v11.15.0][]:

- [CVE-2026-41150](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh): **fix(gantt): limit loop if excluding all dates** (a59ea56174712ee5430dfd5bc877cb5151f501a6)
- [CVE-2026-41148](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-xcj9-5m2h-648r): **fix: prevent unbalanced CSS styles in classDefs** (8fead23c59166b7bab6a39eac81acebee2859102)
- [CVE-2026-41149](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-ghcm-xqfw-q4vr): **fix: create CSS styles using the CSSOM** (4e2d512bf5bf6f9de1a8f0a48da78dc4d09ac4f3)
- [CVE-2026-41159](https://github.com/mermaid-js/mermaid/security/advisories/GHSA-87f9-hvmw-gh4p): **fix: block stylis scope escape** (a9d9f0d8eb790349121508688cd338253fd80d76)
- CVE-2026-41907: **fix: loosen `uuid` dependency range to allow v14**
  We don't use this vulnerable code, but it allows users to silence this warning.
  (e8c70434520dd9226bd442f857970cd211067627)

And other dependency updates.

[Mermaid v11.15.0]: https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0

**Full Changelog**: https://github.com/mermaid-js/mermaid/compare/v10.9.5...v10.9.6