CVE-2026-63416
Last modified
CVE-2026-63416 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL without rejecting dot segments or confirming that the normalized destination remains under the configured export path. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL without rejecting dot segments or confirming that the normalized destination remains under the configured export path. An unauthenticated request containing traversal segments can therefore address unintended routes on the internal export server, and the servlet forwards all request headers and the request body to that destination, allowing arbitrary header injection. Depending on the export service configuration, exploitation can expose administration, debugging, health, or configuration endpoints and can permit unintended internal actions. This issue is fixed in version 30.2.7.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jgraph | drawio | < 30.2.7 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-63416?
How severe is CVE-2026-63416?
How do I fix CVE-2026-63416?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63405AnyCable is a realtime server for reliable two-way communica…5.9
- CVE-2026-63406AnyCable is a realtime server for reliable two-way communica…5.9
- CVE-2026-63407Grav API Plugin is a RESTful API for Grav CMS that provides …8.2
- CVE-2026-63408Grav API Plugin is a RESTful API for Grav CMS that provides …7.5
- CVE-2026-63409Deskflow is a keyboard and mouse sharing app. From 1.17.0 un…8.2
- CVE-2026-6341Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 …4.3
- CVE-2026-63419OpenImageIO is a toolset for reading, writing, and manipulat…7.8
- CVE-2026-6342Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 …4.3
- CVE-2026-63420OpenImageIO is a toolset for reading, writing, and manipulat…5.5
- CVE-2026-63421Keystone is a content management system for Node.js. Prior t…7.5
- CVE-2026-63422OpenImageIO is a toolset for reading, writing, and manipulat…7.8
- CVE-2026-63423During an internal security assessment, a potential vulnerab…7.8
Are you affected by CVE-2026-63416?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
