PT-2026-39197 · Drawio · Drawio

·

CVE-2026-42195

·

Published

2026-05-08

·

Updated

2026-05-09

CVSS v3.1

3.4

Low

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions draw.io versions prior to 29.7.9
Description The application accepts a gitlab URL parameter that overrides the GitLab server URL used during OAuth sign-in. An attacker can use a crafted link to cause the "Authorize in GitLab" dialog to open a popup on a host under their control instead of the legitimate gitlab.com. This behavior can lead to credential fishing and the exfiltration of session state tokens.
Recommendations Update to version 29.7.9.

Exploit

Fix

Open Redirect

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42195
GHSA-8X7J-M8PX-7P8X

Affected Products

Drawio