PT-2026-96147 · Drawio · Drawio
CVE-2026-58504
·
Published
2026-09-21
·
Updated
2026-09-29
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
draw.io versions prior to 30.2.5
Description
Opening or importing a specially crafted .drawio file can lead to the execution of attacker-controlled JavaScript within the draw.io origin. This occurs when selected cells are processed by the
TextFormatPanel.addFont() function in src/main/webapp/js/grapheditor/Format.js. The issue arises because an HTML sibling cell keeps the formatted-label path enabled, while a plain-text sibling with editable=0 is excluded from the merged selection style but remains in the iteration set. Consequently, graph.cellRenderer.getLabelValue() returns the plain-text label without HTML encoding, and mxUtils.canConvertHtmlToSvg() parses it as HTML. Successful exploitation can expose diagram data, browser storage, non-HttpOnly cookies, and allow same-origin actions.Recommendations
Update to version 30.2.5.
Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Drawio