Junglewise Threat Intelligence

CVE-2026-46642: jgraph draw.io XSS in Text Format panel via crafted cell label

CVE-2026-46642 · Severity: medium · CVSS 6.1 · Published 2026-06-10

Technologies: JGraph Draw.Io. Vendors: JGraph.

Executive brief

draw.io is a popular diagramming and whiteboarding application used for creating flowcharts and technical drawings. A security flaw allows an attacker to create a malicious diagram file that, when opened by a user, executes unauthorized code within the user's browser session. This could allow an attacker to steal diagram data, access browser cookies, or redirect the user to malicious websites.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in draw.io prior to version 29.7.12 due to improper sanitization in the 'Convert to SVG' feature-detection routine within the Text Format panel. While the primary rendering path is correctly sanitized using DOMPurify, the Format.js component assigns raw cell labels to a detached element's innerHTML property to inspect tag names. Because browsers trigger 'onerror' events for failed image loads even on detached elements, a crafted <img src=x onerror=...> payload executes immediately upon cell selection. This selection occurs automatically during file import, leading to code execution in the editor's origin. The issue is patched in version 29.7.12 by ensuring labels are sanitized before being processed by the Format panel.

Affected products

  • jgraph draw.io < 29.7.12

Timeline

  • 2026-05-08: patched: Version 29.7.12 released
  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE-2026-46642 published to NVD

References

Related threats