External Control of System or Configuration Setting in draw.io - #VU150674
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive diagram XML.
The vulnerability exists due to external control of a system configuration setting in the export URL handling in Init.js when processing an attacker-controlled export URL parameter. A remote attacker can set an attacker-controlled export endpoint to disclose sensitive diagram XML.
User interaction is required to open a crafted URL and perform a normal export.