Arbitrary JavaScript Execution Vulnerability in draw.io by jgraph
CVE-2026-46642

6.1MEDIUM

Key Information:

Vendor

Jgraph

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-46642?

draw.io, a highly configurable diagramming and whiteboarding tool, exhibits a security vulnerability that permits the execution of arbitrary JavaScript code via specially crafted .drawio files. In versions prior to 29.7.12, the flaw resides in the Text Format panel's feature-detection routine, which fails to properly sanitize cell labels. This oversight allows a crafted payload in an image element to trigger script execution once the corresponding cell is selected. The vulnerability has been addressed in the latest release, version 29.7.12.

Affected Version(s)

drawio < 29.7.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.