CVE-2026-58504 | JGraph draw.io up to 30.2.4 TextFormatPanel Format.js TextFormatPanel.addFont cross site scripting (EUVD-2026-83987)

SecurityVulns

A vulnerability labeled as problematic has been found in JGraph draw.io up to 30.2.4. Affected by this vulnerability is the function TextFormatPanel.addFont of the file src/main/webapp/js/grapheditor/Format.js of the component TextFormatPanel. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as CVE-2026-58504. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More