SB20260917229 - Multiple vulnerabilities in draw.io
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) External Control of System or Configuration Setting (CVE-ID: N/A)
CWE-ID: CWE-15 - External Control of System or Configuration Setting
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to external control of a system configuration setting in the GPT endpoint configuration when processing a gpt-url query parameter. A remote attacker can send a crafted URL that overrides the GPT endpoint to disclose sensitive information.
User interaction is required to open the crafted link and use the GPT feature.
2) External Control of System or Configuration Setting (CVE-ID: N/A)
CWE-ID: CWE-15 - External Control of System or Configuration Setting
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive diagram XML.
The vulnerability exists due to external control of a system configuration setting in the export URL handling in Init.js when processing an attacker-controlled export URL parameter. A remote attacker can set an attacker-controlled export endpoint to disclose sensitive diagram XML.
User interaction is required to open a crafted URL and perform a normal export.
Remediation
Install update from vendor's website.