Mermaid before 8.11.0 allows XSS when the antiscript feature is used.Referenceshttps://github.com/mermaid-js/mermaid/issues/2122https://github.com/mermaid-js/mermaid/pull/2123https://github.com/mermaid-js/mermaid/releases/tag/8.11.0-rc2