CVE-2026-63334 | jgraph draw.io up to 30.2.6 Proxy Servlet Utils.java Utils.sanitizeUrl server-side request forgery
A vulnerability was found in jgraph draw.io up to 30.2.6 and classified as problematic. This affects the function Utils.sanitizeUrl of the file src/main/java/com/mxgraph/online/Utils.java of the component Proxy Servlet. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-63334. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More