draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is false, which affects sel
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-76898 | 7.7 HIGH | draw.io: Unauthenticated SSRF via IPv6 ULA blocklist bypass in /embed2.js |
| CVE-2026-63334 | 6.8 MEDIUM | draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist |
| CVE-2026-58504 | 6.1 MEDIUM | draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46 |
| CVE-2026-63416 | 3.7 LOW | draw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpoints |
暂无评论