Executive brief
draw.io is a popular diagramming and whiteboarding application used for creating flowcharts and technical drawings. A vulnerability in how the application handles GitLab login links allows attackers to redirect users to a malicious website instead of the official GitLab login page. This could lead to users unknowingly entering their credentials into a fake site or having their session tokens stolen, potentially compromising their accounts.
Technical details
The draw.io client fails to validate the 'gitlab' and 'gitlab-id' URL parameters before using them to construct OAuth authorization URLs. An attacker can craft a link containing a malicious URL in these parameters; when a victim clicks 'Authorize in GitLab' within the draw.io interface, the application opens a popup to the attacker-controlled host instead of the legitimate GitLab instance. This enables credential phishing via a spoofed login page and the exfiltration of the OAuth 'state' parameter, which contains a session-scoped CSRF token. Exploitation requires the victim to click a specially crafted link and interact with the authorization dialog. The issue is fixed in version 29.7.9 by requiring an explicit server-side configuration flag to allow custom GitLab URLs.
Affected products
- jgraph draw.io < 29.7.9
Timeline
- 2026-04-20: patched: Version 29.7.9 released
- 2026-04-20: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: CVE published to NVD