Executive brief
mxGraph is a JavaScript library used to create and edit diagrams, including integration with Confluence via the draw.io Diagrams plugin. A flaw in the color field input allows attackers to inject JavaScript code that executes in visitors' browsers, potentially enabling session hijacking, credential theft, or malicious command execution within Confluence.
Technical details
mxGraph through version 4.0.0 contains a cross-site scripting (CWE-79) vulnerability in the color field input handler. The vulnerability exists because user-supplied color values are not properly sanitized before being rendered as HTML/CSS, allowing an attacker to inject arbitrary JavaScript code by crafting a malicious color string (e.g., "onMouseOver=alert(1) a="). The attack requires user interaction (hovering over the diagram element) and affects the Confluence draw.io Diagrams plugin and other products integrating mxGraph. An attacker can execute arbitrary JavaScript in the victim's browser session to perform actions as the victim. The fix was implemented in version 4.0.1 by adding input validation for color codes.
Affected products
- JGraph mxGraph through 4.0.0
Timeline
- 2019-07-01: disclosed
- 2019: patched: Version 4.0.1 released with input validation for color codes
- 2022-05-24: advisory: GHSA-xm59-jvxm-cp3v published