Detects 'Information Disclosure' vulnerability in jgraph/drawio affects v. prior to 18.1.2.


Asset Owner

Estimated Time

10 sec

Scan only one

Domain, Ipv4



jgraph/drawio is an open-source, web-based diagramming software used for creating flowcharts, diagrams, and other visual aids. The platform is trusted by individuals and businesses alike for its intuitive interface and easy collaboration features. However, a recent discovery has exposed a critical security vulnerability that can lead to exposure of sensitive information to unauthorized actors. 

The CVE-2022-1815 vulnerability detected in jgraph/drawio can be exploited when a user uploads a file with an arbitrary extension, which can then be accessed by the attacker. This unauthorized access can lead to the disclosure of sensitive data and the potential compromise of the entire system. The vulnerability exists prior to version 18.1.2 of the software. 

The CVE-2022-1815 vulnerability detected in jgraph/drawio can be exploited when a user uploads a file with an arbitrary extension, which can then be accessed by the attacker. This unauthorized access can lead to the disclosure of sensitive data and the potential compromise of the entire system. The vulnerability exists prior to version 18.1.2 of the software. 

The potential consequences of this vulnerability are severe. An attacker can extract confidential information from the uploaded file, such as login credentials or financial data, resulting in financial loss, reputational damage, and legal repercussions. The exposure of personally identifiable information (PII) can also lead to identity theft, further amplifying the damage caused by the vulnerability.



