Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Fl3X1Nz

#52854of 53,633
3.4Total CVSS
Vulnerabilities · 1
PT-2026-39197
3.4
2026-05-08
Drawio · Drawio · CVE-2026-42195
**Name of the Vulnerable Software and Affected Versions** draw.io versions prior to 29.7.9 **Description** The application accepts a `gitlab` URL parameter that overrides the GitLab server URL used during OAuth sign-in. An attacker can use a crafted link to cause the "Authorize in GitLab" dialog to open a popup on a host under their control instead of the legitimate gitlab.com. This behavior can lead to credential fishing and the exfiltration of session state tokens. **Recommendations** Update to version 29.7.9.