SB2026090756 - Server-Side Request Forgery (SSRF) in draw.io
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information from internal services.
The vulnerability exists due to improper restriction of server-side request forgery in the validatedAddress() method when processing URLs containing IPv6 transition addresses. A remote attacker can send a crafted request to the embed or proxy endpoint to disclose sensitive information from internal services.
The embed endpoint is always enabled, while exploitation through the proxy endpoint requires the proxy feature to be enabled.
Remediation
Install update from vendor's website.