CVE-2022-46180: Arbitrary HTML injection in discourse-mermaid-theme-component
Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the main branch of the GitHub repository, with 1.1.0 named as a patched version. Admins can update the theme component through the admin UI. As a workaround, admins can temporarily disable discourse-mermaid-theme-component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46180?
CVE-2022-46180 is classified as a high severity vulnerability due to the potential for arbitrary HTML injection.
How do I fix CVE-2022-46180?
To fix CVE-2022-46180, upgrade the Discourse Mermaid component to version 1.1.0 or later.
Who is affected by CVE-2022-46180?
Users of Discourse using the discourse-mermaid-theme-component version between 1.0.0 and 1.1.0 are affected by CVE-2022-46180.
What are the potential impacts of CVE-2022-46180?
The potential impacts of CVE-2022-46180 include the ability for users to inject malicious HTML, possibly leading to cross-site scripting attacks.
What versions are vulnerable to CVE-2022-46180?
Versions of the Discourse Mermaid component from 1.0.0 to 1.1.0 are vulnerable to CVE-2022-46180.