Users that can create posts are able to inject arbitrary HTML on that post.
Patches
The issue has been fixed on the main branch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> discourse-mermaid-theme-component -> Check for Updates)
Workarounds
Alternatively, admins can temporarily disable discourse-mermaid-theme-component.
Impact
Users that can create posts are able to inject arbitrary HTML on that post.
Patches
The issue has been fixed on the
mainbranch. Admins can update the theme component through the admin UI (Customize -> Themes -> Components -> discourse-mermaid-theme-component -> Check for Updates)Workarounds
Alternatively, admins can temporarily disable discourse-mermaid-theme-component.