Medium severity6.1NVD Advisory· Published Sep 8, 2022· Updated Jun 17, 2026
CVE-2022-3138
CVE-2022-3138
Description
Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- jgraph/jgraph/drawiov5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/jgraph/drawio/commit/b5dfeb238369d664fb06a95e2179236b0e75f366nvdPatchThird Party Advisory
- huntr.dev/bounties/1816a207-6abf-408c-b19a-e497e24172b3nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.