CVE-2026-63416 | JGraph draw.io up to 30.2.6 Export Service ExportProxyServlet.java request.getPathInfo path traversal (EUVD-2026-83988)

SecurityVulns

A vulnerability categorized as critical has been discovered in JGraph draw.io up to 30.2.6. This impacts the function request.getPathInfo of the file src/main/java/com/mxgraph/online/ExportProxyServlet.java of the component Export Service. Such manipulation leads to path traversal.

This vulnerability is traded as CVE-2026-63416. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More