CVE-2026-63373 | JGraph draw.io up to 30.2.6 OAuth Callback AbsAuth.java improper authorization
A vulnerability classified as critical was found in JGraph draw.io up to 30.2.6. This issue affects some unknown processing of the file src/main/java/com/mxgraph/online/AbsAuth.java of the component OAuth Callback Handler. Such manipulation leads to improper authorization.
This vulnerability is referenced as CVE-2026-63373. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More