JavaScript Execution Vulnerability in draw.io by JGraph
CVE-2026-58504

6.1MEDIUM

Key Information:

Vendor

Jgraph

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-58504?

draw.io is a widely used diagramming and whiteboarding application. A vulnerability exists in versions prior to 30.2.5, allowing the execution of attacker-controlled JavaScript via crafted .drawio files. This occurs when selected cells are processed incorrectly, leading to potential exposure of sensitive information such as diagram data, browser storage, and non-HttpOnly cookies. The flaw has been addressed in version 30.2.5, highlighting the importance of updating to the latest version to mitigate associated risks.

Affected Version(s)

drawio < 30.2.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.