draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and fd00::, but the JDK re
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63334 | 6.8 MEDIUM | draw.io: SSRF via DNS rebinding in ProxyServlet bypasses private IP blocklist |
| CVE-2026-58504 | 6.1 MEDIUM | draw.io: Stored XSS on file open via editable=0 sibling cell — patch bypass of CVE-2026-46 |
| CVE-2026-63373 | 4.2 MEDIUM | draw.io: OAuth CSRF via missing state validation on self-hosted deployments allows session |
| CVE-2026-63416 | 3.7 LOW | draw.io: Path traversal in ExportProxyServlet allows access to arbitrary backend endpoints |
No comments yet