External Control of System or Configuration Setting in draw.io - #VU150673

 

External Control of System or Configuration Setting in draw.io - #VU150673

Published: September 17, 2026


Vulnerability identifier: #VU150673
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-15
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to external control of a system configuration setting in the GPT endpoint configuration when processing a gpt-url query parameter. A remote attacker can send a crafted URL that overrides the GPT endpoint to disclose sensitive information.

User interaction is required to open the crafted link and use the GPT feature.


Affected software

draw.io

Remediation

Install security update from vendor's website.

draw.io - update to 31.4.6

External References

Related Security Bulletins