Cross-Site Scripting Vulnerability in Excalidraw's Imported File Handler
CVE-2026-97224
5.3MEDIUM
What is CVE-2026-97224?
A vulnerability exists in Excalidraw versions up to 0.18.1, specifically within an unknown function of the Imported File Handler component located in the file packages/excalidraw/data/restore.ts. This flaw allows attackers to exploit cross-site scripting (XSS) by manipulating the argument 'customData.generationData.html'. The exploit can be executed remotely, making it a serious risk for users. Despite early notification to the vendor regarding this issue, there has been no response.
Affected Version(s)
Excalidraw 0.18.0
Excalidraw 0.18.1
