Cross-Site Scripting Vulnerability in Excalidraw's Imported File Handler
CVE-2026-97224

5.3MEDIUM

Key Information:

Vendor

Excalidraw

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97224?

A vulnerability exists in Excalidraw versions up to 0.18.1, specifically within an unknown function of the Imported File Handler component located in the file packages/excalidraw/data/restore.ts. This flaw allows attackers to exploit cross-site scripting (XSS) by manipulating the argument 'customData.generationData.html'. The exploit can be executed remotely, making it a serious risk for users. Despite early notification to the vendor regarding this issue, there has been no response.

Affected Version(s)

Excalidraw 0.18.0

Excalidraw 0.18.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kaardeco (VulDB User)
VulDB CNA Team
.