Medium severity6.1NVD Advisory· Published Jul 1, 2019· Updated Jun 17, 2026
CVE-2019-13127
CVE-2019-13127
Description
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mxgraphnpm | < 4.0.1 | 4.0.1 |
Affected products
4- mxGraph/draw.io Diagrams plugin for Confluencedescription
Patches
Vulnerability mechanics
References
5- github.com/jgraph/mxgraph/commit/76e8e2809b622659a9c5ffdc4f19922b7a68cfa3nvdPatchThird Party AdvisoryWEB
- www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2019-032.txtnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-xm59-jvxm-cp3vghsaADVISORY
- marketplace.atlassian.com/apps/1210933/draw-io-diagrams-for-confluence/version-historynvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-13127ghsaADVISORY
News mentions
0No linked articles in our index yet.