CVE-2022-1575: Arbitrary Code Execution through Sanitizer Bypass in jgraph/drawio
Published May 5, 2022
·Updated
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
Affected Software
1 affected component
Diagrams Drawio<18.0.0
Remediation
Event History
May 5, 2022
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-1575.
2
What is the severity of CVE-2022-1575?
The severity of CVE-2022-1575 is critical with a CVSS score of 9.6.
3
What is the affected software for CVE-2022-1575?
The affected software for CVE-2022-1575 is Diagrams Drawio version up to (but not including) 18.0.0.
4
How can an attacker exploit CVE-2022-1575?
An attacker can exploit CVE-2022-1575 to execute arbitrary code remotely or perform stored XSS attacks.
5
Is there a fix available for CVE-2022-1575?
Yes, the fix for CVE-2022-1575 is available in version 18.0.0 of Diagrams Drawio.