CVE-2026-7182

N/A Unknown
Published: May 15, 2026 Modified: May 15, 2026
View on NVD

Description

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization.Β An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated pdf. This issue was fixed in version 1.1.1.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)