External Control of System or Configuration Setting in draw.io - #VU150673
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to external control of a system configuration setting in the GPT endpoint configuration when processing a gpt-url query parameter. A remote attacker can send a crafted URL that overrides the GPT endpoint to disclose sensitive information.
User interaction is required to open the crafted link and use the GPT feature.