Information disclosure in draw.io - #VU144557
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of external references in Graph.isStyleAllowed when processing CSS in diagram labels. A remote attacker can supply a crafted diagram that triggers external image requests and conditional CSS-based data leakage to disclose sensitive information.
User interaction is required to view a crafted diagram, and the issue is particularly exposed when untrusted diagrams are rendered inline via GraphViewer in a page that contains DOM secrets.