Impact
The flaw allows an unauthenticated user to issue a request to /embed2.js with a fetch parameter pointing to an IPv6 Unique Local Address. Because the server expands the address form, the check for fc00:: and fd00:: prefixes fails, letting the server fetch and return the content of internal services, such as AWS metadata endpoints. The response is reflected back to the requester, revealing credentials or other sensitive data.
Affected Systems
The vulnerability exists in draw.io (jgraph:drawio) for all releases prior to version 30.3.8. Users of 30.3.8 or newer are not affected.
Risk and Exploitability
With a CVSS score of 7.7 and no mitigation in place, the attack can be carried out by anyone who can reach the exposed URL. The EPSS score is not available, and the issue is not listed in CISA KEV. Because the attack requires no authentication, no proxy flag, and no DNS rebinding, the likelihood of exploitation is high in environments where the endpoint is publicly reachable.
OpenCVE Enrichment