Junglewise Threat Intelligence

CVE-2026-42195: jgraph draw.io open redirect and token leak in GitLab OAuth flow

CVE-2026-42195 · Severity: low · CVSS 3.4 · Published 2026-05-08

Technologies: JGraph Draw.Io. Vendors: JGraph.

Executive brief

draw.io is a popular diagramming and whiteboarding application used for creating flowcharts and technical drawings. A vulnerability in how the application handles GitLab login links allows attackers to redirect users to a malicious website instead of the official GitLab login page. This could lead to users unknowingly entering their credentials into a fake site or having their session tokens stolen, potentially compromising their accounts.

Technical details

The draw.io client fails to validate the 'gitlab' and 'gitlab-id' URL parameters before using them to construct OAuth authorization URLs. An attacker can craft a link containing a malicious URL in these parameters; when a victim clicks 'Authorize in GitLab' within the draw.io interface, the application opens a popup to the attacker-controlled host instead of the legitimate GitLab instance. This enables credential phishing via a spoofed login page and the exfiltration of the OAuth 'state' parameter, which contains a session-scoped CSRF token. Exploitation requires the victim to click a specially crafted link and interact with the authorization dialog. The issue is fixed in version 29.7.9 by requiring an explicit server-side configuration flag to allow custom GitLab URLs.

Affected products

  • jgraph draw.io < 29.7.9

Timeline

  • 2026-04-20: patched: Version 29.7.9 released
  • 2026-04-20: advisory: GitHub Security Advisory published
  • 2026-05-08: disclosed: CVE published to NVD

References

Related threats