PT-2026-96147 · Drawio · Drawio

CVE-2026-58504

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions draw.io versions prior to 30.2.5
Description Opening or importing a specially crafted .drawio file can lead to the execution of attacker-controlled JavaScript within the draw.io origin. This occurs when selected cells are processed by the TextFormatPanel.addFont() function in src/main/webapp/js/grapheditor/Format.js. The issue arises because an HTML sibling cell keeps the formatted-label path enabled, while a plain-text sibling with editable=0 is excluded from the merged selection style but remains in the iteration set. Consequently, graph.cellRenderer.getLabelValue() returns the plain-text label without HTML encoding, and mxUtils.canConvertHtmlToSvg() parses it as HTML. Successful exploitation can expose diagram data, browser storage, non-HttpOnly cookies, and allow same-origin actions.
Recommendations Update to version 30.2.5.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58504
GHSA-C76X-R78M-PHWX

Affected Products

Drawio