sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
{ "binaries": [ { "binary_version": "8.13.8+~cs10.4.16-1", "binary_name": "node-mermaid" } ] }