PT-2026-96150 · Drawio · Drawio

CVE-2026-63416

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions draw.io versions prior to 30.2.7
Description The ExportProxyServlet.java component uses request.getPathInfo() to construct a proxyPath which is appended to the EXPORT URL. Because the application fails to reject dot segments or verify that the normalized destination remains within the configured export path, unauthenticated requests containing traversal segments can access unintended routes on the internal export server. Additionally, the servlet forwards all request headers and the request body to the destination, enabling arbitrary header injection. This may expose administration, debugging, health, or configuration endpoints and allow unauthorized internal actions.
Recommendations Update to version 30.2.7.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63416
GHSA-3PQ9-9HG4-GGFW

Affected Products

Drawio