{"id":"CVE-2026-76898","published":"2026-09-21T17:18:50.350","lastModified":"2026-09-21T17:18:50.350","description":"draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and fd00::, but the JDK returns the expanded address form, so the fc00::/7 range, including the AWS metadata range fd00:ec2::/32, is not blocked. An unauthenticated request to /embed2.js?fetch= can therefore make src/main/java/com/mxgraph/online/EmbedServlet2.java fetch an IPv6 ULA internal resource and reflect the response to the requester. Utils.validatedAddress() uses the same private-address check for the separate ProxyServlet path, which requires ENABLE_DRAWIO_PROXY=1. The primary /embed2.js path requires no proxy feature flag or DNS rebinding, and it can disclose cloud metadata credentials or data from other IPv6-reachable internal services. This issue is fixed in version 30.3.8.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://github.com/jgraph/drawio/commit/73c4a91196246bbdb60f52b15871e82006b7972d","tags":[]},{"url":"https://github.com/jgraph/drawio/releases/tag/v30.3.8","tags":[]},{"url":"https://github.com/jgraph/drawio/security/advisories/GHSA-m3q9-cwfq-hcjc","tags":[]}],"exploitRefs":[{"url":"https://github.com/jgraph/drawio/commit/73c4a91196246bbdb60f52b15871e82006b7972d","tags":[]},{"url":"https://github.com/jgraph/drawio/releases/tag/v30.3.8","tags":[]},{"url":"https://github.com/jgraph/drawio/security/advisories/GHSA-m3q9-cwfq-hcjc","tags":[]}],"hasPoc":true,"ai":null}