Impact
draw.io allows an attacker to inject a session token through an OAuth callback by bypassing state token validation in self-hosted deployments. The flaw permits a victim to be authenticated as the attacker’s cloud‑storage identity, enabling the attacker to perform cloud actions under the victim’s session without the victim’s knowledge. The primary consequence is loss of session integrity and potential misattribution of cloud activity, though existing victim files are not directly exposed.
Affected Systems
The vulnerability affects jgraph:drawio installations running Docker or WAR images prior to version 30.2.7. It impacts the Google Drive, OneDrive, GitHub, GitLab, and Dropbox integration handlers within those self‑hosted deployments.
Risk and Exploitability
The flaw has a CVSS score of 4.2, indicating moderate severity. The EPSS score is not available and the issue is not listed in CISA KEV. Exploitation requires an attacker to supply a forged authorization code and have the victim visit the malicious callback URL, suggesting the attack vector is most likely social engineering or phishing. Given the absence of known public exploits and moderate CVSS, the overall risk is considered moderate, but the impact on session integrity warrants prompt attention.
OpenCVE Enrichment