Server-Side Request Forgery (SSRF) in draw.io - #VU144555
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to send server-side requests to internal CGNAT hosts.
The vulnerability exists due to improper input validation in ProxyServlet / Utils.sanitizeUrl when handling requests to the optional /proxy endpoint. A remote attacker can send a specially crafted request to send server-side requests to internal CGNAT hosts.
Only instances with ENABLE_DRAWIO_PROXY=1 are vulnerable.