Server-Side Request Forgery Vulnerability in draw.io by jgraph
CVE-2026-63334
6.8MEDIUM
What is CVE-2026-63334?
The draw.io application, a versatile diagramming and whiteboarding tool, is susceptible to server-side request forgery when deployed with ENABLE_DRAWIO_PROXY=1, prior to version 30.2.7. This vulnerability arises from improper DNS resolution checks in the URL sanitization process. An attacker can exploit this flaw by supplying a malicious hostname, which can initially resolve publicly during validation but subsequently redirect to a private or sensitive internal address, exposing cloud instance metadata or revealing responses from restricted HTTP services via the proxy. Users are advised to upgrade to version 30.2.7 to mitigate this risk.
Affected Version(s)
drawio < 30.2.7
