Collected research
draw.io CVEs
Two draw.io flaws found by source review: the /proxy endpoint's blocklist of private hosts is defeated by http://0:8080/, giving SSRF; and an isAbsolute check returns false when URI parsing throws, so the malformed https:// @evil.com (note the space) passes as a relative path while Chrome still follows it, forwarding the victim's GitHub OAuth token to the attacker.
Record
- Researcher
- @caioluders
- Published by
- lude.rs
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @caioluders, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .