Server-Side Request Forgery (SSRF) in draw.io - #VU147249
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information from internal services.
The vulnerability exists due to improper restriction of server-side request forgery in the validatedAddress() method when processing URLs containing IPv6 transition addresses. A remote attacker can send a crafted request to the embed or proxy endpoint to disclose sensitive information from internal services.
The embed endpoint is always enabled, while exploitation through the proxy endpoint requires the proxy feature to be enabled.