Server-Side Request Forgery (SSRF) in draw.io - #VU147249

 

Server-Side Request Forgery (SSRF) in draw.io - #VU147249

Published: September 7, 2026


Vulnerability identifier: #VU147249
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information from internal services.

The vulnerability exists due to improper restriction of server-side request forgery in the validatedAddress() method when processing URLs containing IPv6 transition addresses. A remote attacker can send a crafted request to the embed or proxy endpoint to disclose sensitive information from internal services.

The embed endpoint is always enabled, while exploitation through the proxy endpoint requires the proxy feature to be enabled.


Affected software

draw.io

Remediation

Install security update from vendor's website.

draw.io - update to 31.4.4

External References

Related Security Bulletins