Arbitrary JavaScript Execution Vulnerability in draw.io by jgraph
CVE-2026-46642
6.1MEDIUM
What is CVE-2026-46642?
draw.io, a highly configurable diagramming and whiteboarding tool, exhibits a security vulnerability that permits the execution of arbitrary JavaScript code via specially crafted .drawio files. In versions prior to 29.7.12, the flaw resides in the Text Format panel's feature-detection routine, which fails to properly sanitize cell labels. This oversight allows a crafted payload in an image element to trigger script execution once the corresponding cell is selected. The vulnerability has been addressed in the latest release, version 29.7.12.
Affected Version(s)
drawio < 29.7.12
