CVE-2026-97224
Last modified
CVE-2026-97224 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File Handler.
Description
A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File Handler. Performing a manipulation of the argument customData.generationData.html results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | Excalidraw | 0.18.0; 0.18.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-97224?
How severe is CVE-2026-97224?
How do I fix CVE-2026-97224?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-97182A security vulnerability has been detected in halo-dev Halo …7.3
- CVE-2026-97185A flaw was found in GIMP. When processing a specially crafte…7.8
- CVE-2026-9719The LatePoint – Calendar Booking Plugin for Appointments and…4.3
- CVE-2026-9720The Facturación Electrónica Costa Rica plugin for WordPress …4.3
- CVE-2026-9721The Book a Room Event Calendar plugin for WordPress is vulne…4.3
- CVE-2026-9722The Laiser Tag plugin for WordPress is vulnerable to Cross-S…4.3
- CVE-2026-97225A flaw has been found in DbGate up to 7.2.5-beta.5. This aff…6.3
- CVE-2026-97226A vulnerability has been found in DbGate up to 7.2.5/7.3.1-p…6.3
- CVE-2026-9723The Google Plus One Bottom plugin for WordPress is vulnerabl…4.3
- CVE-2026-97231A vulnerability was found in volotat Anagnorisis up to 0.3.1…7.3
- CVE-2026-97232A vulnerability was determined in volotat Anagnorisis up to …6.3
- CVE-2026-97233A vulnerability was identified in volotat Anagnorisis up to …3.5
Are you affected by CVE-2026-97224?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
