PT-2026-97850 · Unknown · Excalidraw

·

CVE-2026-97224

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Excalidraw versions prior to 0.18.2
Description An issue exists in the Imported File Handler component within the packages/excalidraw/data/restore.ts file. A remote attacker can perform cross-site scripting (XSS)—a technique used to inject malicious scripts into web pages viewed by other users—by manipulating the customData.generationData.html argument.
Recommendations Update Excalidraw to a version newer than 0.18.1. Restrict the use of the customData.generationData.html argument in the Imported File Handler until a patch is applied.

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97224

Affected Products

Excalidraw