draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java performs the private-address
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76898 | 7.7 HIGH | draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js |
| CVE-2026-58504 | 6.1 MEDIUM | draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46 |
| CVE-2026-63373 | 4.2 MEDIUM | draw.io: OAuth CSRF via missing state validation on self-hosted deployments allows session |
| CVE-2026-63416 | 3.7 LOW | draw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpoints |
No comments yet