OAuth Callback Handler Vulnerability in draw.io by jgraph
CVE-2026-63373
What is CVE-2026-63373?
The draw.io application, utilized for diagramming and whiteboarding, contains an OAuth callback handler vulnerability that affects self-hosted Docker and WAR deployments prior to version 30.2.7. This issue arises when the stateToken and cookieToken comparison is skipped under certain conditions, allowing attackers to provide an unauthorized authorization code. If a victim is misled to visit a malicious callback URL, their session can be hijacked, enabling the attacker to impersonate the victim for cloud-storage actions with integrations like Google Drive, OneDrive, GitHub, GitLab, and Dropbox. While this vulnerability does not grant access to the victim's cloud files directly, it compromises session integrity and can lead to significant security risks. This issue has been rectified in version 30.2.7.
Affected Version(s)
drawio < 30.2.7
