Web Hack List

Other nomination

draw.io CVEs

Two draw.io flaws found by source review: the /proxy endpoint's blocklist of private hosts is defeated by http://0:8080/, giving SSRF; and an isAbsolute check returns false when URI parsing throws, so the malformed https:// @evil.com (note the space) passes as a relative path while Chrome still follows it, forwarding the victim's GitHub OAuth token to the attacker.

Record

Researcher
@caioluders

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @caioluders, first published at the original source. Preserved copies are kept so the citation survives its host.