CVE-2026-63373: draw.io: OAuth CSRF via missing state validation on self-hosted deployments allows session token injection

Published Sep 21, 2026
·
Updated

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever ISGAE is false, which affects self-hosted Docker and WAR deployments. An attacker can provide an authorization code for the attacker's cloud-storage identity and induce a victim to visit a callback URL, causing the victim's draw.io session to become authenticated as the attacker identity without a valid state binding. The shared handler affects Google Drive, OneDrive, GitHub, GitLab, and Dropbox integrations. The victim can then unknowingly perform cloud-storage actions under the attacker's identity, causing session integrity loss and misattribution, but the identity binding does not itself grant access to existing victim cloud files. This issue is fixed in version 30.2.7.

Affected Software

1 affected component
diagrams.net draw.io<30.2.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade draw.io to a version that resolves this vulnerability.

    Fixed in 30.2.7

Event History

Sep 21, 2026
CVE Published
via MITRE·04:29 PM
Data Sourced
via MITRE·04:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

The issue affects self-hosted draw.io Docker and WAR deployments where IS_GAE is false. The vulnerable OAuth callback handler is shared by the Google Drive, OneDrive, GitHub, GitLab, and Dropbox integrations.

2

What does an attacker need to exploit this?

An attacker needs an authorization code for their own cloud-storage identity and must induce a victim to visit a crafted OAuth callback URL. No authentication is required of the attacker, but victim interaction is required.

3

What is the impact on the victim's cloud data?

The victim's draw.io session can be bound to the attacker's cloud-storage identity, so actions may be performed and attributed under that identity. This binding flaw does not itself give the attacker access to the victim's existing cloud files.

4

How can this be remediated?

Upgrade draw.io to version 30.2.7, which fixes the missing state-token validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203