Skip to content

Known CVE

draw.io < 18.0.5 - Server Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) vulnerability in draw.io (also known as diagrams.net) prior to version 18.0.5 allows attackers to bypass URL validation restrictions in the ProxyServlet component. The vulnerability exists because the application does not properly validate URLs passed to its proxy endpoint, allowing attackers to make requests to internal services or external servers. This can lead to unauthorized access to internal resources and potential data exfiltration.

CVE-2022-1711

High2022CVSS 7.5CWE-918

cve2022 · ssrf · drawio · diagrams · jgraph · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website