JavaScript Execution Vulnerability in draw.io by JGraph
CVE-2026-58504
6.1MEDIUM
What is CVE-2026-58504?
draw.io is a widely used diagramming and whiteboarding application. A vulnerability exists in versions prior to 30.2.5, allowing the execution of attacker-controlled JavaScript via crafted .drawio files. This occurs when selected cells are processed incorrectly, leading to potential exposure of sensitive information such as diagram data, browser storage, and non-HttpOnly cookies. The flaw has been addressed in version 30.2.5, highlighting the importance of updating to the latest version to mitigate associated risks.
Affected Version(s)
drawio < 30.2.5
